Path Traversal Vulnerability in FW Gallery by Fastw3b LLC
CVE-2025-49415

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49415?

A vulnerability has been identified in the FW Gallery product developed by Fastw3b LLC, which allows for Path Traversal exploitation. This flaw affects all versions from n/a to 8.0.0, enabling unauthorized access to restricted directories. If successfully exploited, an attacker could potentially manipulate the application's file structure, leading to unauthorized data exposure or deletion. It is essential for users of FW Gallery to review their configurations and implement necessary security measures to mitigate this risk.

Affected Version(s)

FW Gallery <= 8.0.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.