PT-2025-52582 · WordPress · Image Photo Gallery Final Tiles Grid

Athiwat Tiprasaharn

+5

·

Published

2025-12-21

·

Updated

2025-12-21

·

CVE-2025-13693

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Photo Gallery Final Tiles Grid versions prior to 3.6.9
Description The Image Photo Gallery Final Tiles Grid plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is due to inadequate input sanitization and output escaping in the 'Custom scripts' setting. Authenticated attackers with Author-level access or higher can inject arbitrary web scripts into pages. These scripts will execute when a user accesses the affected page.
Recommendations Update Image Photo Gallery Final Tiles Grid to version 3.6.9 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13693

Affected Products

Image Photo Gallery Final Tiles Grid