Unauthorized Data Modification in Image Gallery Plugin for WordPress
CVE-2025-14003
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 December 2025
What is CVE-2025-14003?
The Image Gallery β Photo Grid & Video Gallery plugin for WordPress is prone to unauthorized data modification due to a lack of proper capability checks within the add_images_to_gallery_callback() function. This vulnerability affects all versions up to and including 2.13.3, allowing authenticated users with Author-level privileges and above to insert images into Modula galleries that belong to other users. This security oversight can lead to unauthorized modifications, potentially compromising the integrity of gallery content across affected sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Image Gallery β Photo Grid & Video Gallery * <= 2.13.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved