PT-2025-47703 · WordPress · Wp Audio Gallery

CVE-2025-13322

·

Publicado

2025-11-21

·

Atualizado

2025-11-26

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP AUDIO GALLERY plugin for WordPress versions prior to 2.1
Description The WP AUDIO GALLERY plugin for WordPress is susceptible to arbitrary file deletion. This is caused by inadequate file path validation within the wpag uploadaudio callback() AJAX handler, specifically concerning the audio upload parameter before it is passed to the unlink() function. This allows authenticated attackers with subscriber-level access or higher to delete arbitrary files on the server. Deletion of critical files, such as wp-config.php, can lead to remote code execution.
Recommendations Update the WP AUDIO GALLERY plugin to version 2.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13322

Produtos afetados

Wp Audio Gallery