Description
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to move arbitrary image files on the server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 17 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpchill Wpchill image Photo Gallery Final Tiles Grid |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpchill Wpchill image Photo Gallery Final Tiles Grid |
Sat, 15 Nov 2025 06:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-17T18:46:19.807Z
Reserved: 2025-10-29T20:58:17.650Z
Link: CVE-2025-12494
Updated: 2025-11-17T18:46:16.056Z
Status : Awaiting Analysis
Published: 2025-11-15T06:15:42.213
Modified: 2025-11-18T14:06:55.963
Link: CVE-2025-12494
No data.
OpenCVE Enrichment
Updated: 2025-11-15T22:07:23Z
Weaknesses