The NextGEN Gallery plugin for WordPress has a security vulnerability that could allow attackers with administrator-level privileges to read and delete any file. This vulnerability is present in versions of the plugin up to and including version 3.37. It is caused by a lack of sufficient validation within the gallery_edit function.