WordPress · Image Photo Gallery Final Tiles Grid · CVE-2025-14455
**Name of the Vulnerable Software and Affected Versions**
Image Photo Gallery Final Tiles Grid plugin for WordPress versions up to and including 3.6.7
**Description**
The Image Photo Gallery Final Tiles Grid plugin for WordPress does not properly verify user authorization for gallery management functions. This allows authenticated attackers with Contributor-level access or higher to delete, modify, or clone galleries created by any user, including administrators.
**Recommendations**
Update the Image Photo Gallery Final Tiles Grid plugin to a version later than 3.6.7.