Arbitrary File Upload Vulnerability in FW Gallery by Fastw3b LLC
CVE-2025-49414

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 July 2025

What is CVE-2025-49414?

The FW Gallery plugin by Fastw3b LLC presents a security risk due to an arbitrary file upload vulnerability. This flaw allows attackers to upload malicious files, potentially leading to unauthorized access or data manipulation. Affected versions range from n/a up to 8.0.0, making it crucial for users to review their installations and apply necessary security measures.

Affected Version(s)

FW Gallery <= 8.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.