UNKNOWN (0.0)
    Plugin

    Path Traversal Vulnerability in Image Gallery Plugin for WordPress

    Published Date: 12/12/2025
    CVE ID: CVE-2025-13891

    Summary

    The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is affected by a path traversal vulnerability due to inadequate validation in the modula_list_folders AJAX endpoint. This flaw permits authenticated users with Author-level or higher access to gain unauthorized directory enumeration on the server hosting WordPress.

    Vulnerability Details

    The vulnerability exists in all versions of the Image Gallery – Photo Grid & Video Gallery plugin up to, and including, 2.13.3. The exploit stems from the modula_list_folders AJAX endpoint, which does not enforce rigorous path validation or base directory constraints. Despite the plugin requiring users to have Author-level access or higher to use the endpoint, it does not ensure that directory paths supplied by users are constrained to benign, expected directories. As a result, an attacker with adequate permissions can manipulate directory paths, facilitating traversal across directory boundaries. This may allow the attacker to list directory contents outside of the intended scope, potentially accessing sensitive files that should not be exposed.

    Recommendations

    To mitigate this vulnerability, ensure that all user inputs related to directory paths are appropriately sanitized and validated to conform to approved directories. Implement strict directory traversal checks and consider employing validation libraries or built-in path resolution functions to enforce these restrictions. Additionally, review and modify user permissions to minimize unnecessary access and capabilities that might increase the risk of exploitation.

    Available Fixes

    Last Updated: 12/13/2025
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2025 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More