Stored Cross-Site Scripting Vulnerability in Image Photo Gallery Final Tiles Grid Plugin for WordPress
CVE-2025-13693

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 December 2025

What is CVE-2025-13693?

The Image Photo Gallery Final Tiles Grid plugin for WordPress allows authenticated users with Author-level access or higher to exploit a vulnerability in the 'Custom scripts' setting. Due to insufficient input sanitization and output escaping, attackers can inject arbitrary web scripts. These scripts are then executed when a user accesses an affected page, potentially leading to unauthorized actions and data exposure.

Affected Version(s)

Image Photo Gallery Final Tiles Grid * <= 3.6.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
Itthidej Aramsri
Powpy
Waris Damkham
Varakorn Chanthasri
Peerapat Samatathanyakorn
.
CVE-2025-13693 : Stored Cross-Site Scripting Vulnerability in Image Photo Gallery Final Tiles Grid Plugin for WordPress