NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
WordPress 6.5.x
Exploit
CVE-2013-3684
NVD
Refer to CVE-2013-3684 NVD advisory