PT-2025-51228 · WordPress+1 · Image Gallery – Photo Grid & Video Gallery+1

Athiwat Tiprasaharn

+6

·

Published

2025-12-15

·

Updated

2025-12-15

·

CVE-2025-14003

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Gallery – Photo Grid & Video Gallery plugin for WordPress versions up to and including 2.13.3
Description The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is susceptible to unauthorized data modification. A missing capability check within the add images to gallery callback() function allows authenticated attackers with Author-level access or higher to add images to Modula galleries belonging to other users.
Recommendations Update to version 2.13.4 or later. As a temporary workaround, restrict access to the add images to gallery callback() function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14003

Affected Products

Image Gallery – Photo Grid & Video Gallery
Modula