CVE-2025-12494
BaseFortify
Publication date: 2025-11-15
Last updated on: 2025-11-15
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | image_gallery_photo_grid_and_video_gallery | 2.12.28 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-285 | The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Image Gallery β Photo Grid & Video Gallery plugin for WordPress, where an authenticated user with author-level access or higher can exploit insufficient file path validation in the ajax_import_file function to delete or move arbitrary image files on the server.
How can this vulnerability impact me? :
An attacker with author-level access or above can delete or move image files on the server, potentially disrupting website content or causing loss of important media files. This could affect the integrity and availability of the website's images.