The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to move arbitrary image files on the server.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 15 Nov 2025 06:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-15T05:45:34.066Z
Reserved: 2025-10-29T20:58:17.650Z
Link: CVE-2025-12494
No data.
Status : Received
Published: 2025-11-15T06:15:42.213
Modified: 2025-11-15T06:15:42.213
Link: CVE-2025-12494
No data.
OpenCVE Enrichment
No data.