Missing Authorization Vulnerability in 3D Image Gallery Plugin by bPlugins
CVE-2025-49394
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-49394?
A missing authorization vulnerability exists in the 3D Image Gallery plugin by bPlugins, which allows unauthorized access to functionality that is not properly constrained by ACLs. This flaw affects the plugin versions from n/a up to and including 1.0.7, potentially exposing sensitive data and functionalities related to creating and displaying photo galleries and albums. Attackers could exploit this issue to gain unauthorized access, leading to possible data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Image Gallery block β Create and display photo gallery/photo album. <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved