Stored Cross-Site Scripting Vulnerability in Image Photo Gallery Final Tiles Grid Plugin for WordPress
CVE-2025-13693
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 December 2025
What is CVE-2025-13693?
The Image Photo Gallery Final Tiles Grid plugin for WordPress allows authenticated users with Author-level access or higher to exploit a vulnerability in the 'Custom scripts' setting. Due to insufficient input sanitization and output escaping, attackers can inject arbitrary web scripts. These scripts are then executed when a user accesses an affected page, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
Image Photo Gallery Final Tiles Grid * <= 3.6.8
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Athiwat Tiprasaharn
Itthidej Aramsri
Powpy
Waris Damkham
Varakorn Chanthasri
Peerapat Samatathanyakorn