FW Gallery <= 8.0.0 - Unauthenticated Arbitrary File Upload
critical
The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers to upload arbitrary...
- CVSS:
- 9.8
- Affected:
- up to 8.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 30, 2025
CVE-2025-49414 on NVD →
FW Gallery <= 8.0.0 - Unauthenticated Local File Inclusion
high
The FW Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...
- CVSS:
- 8.1
- Affected:
- up to 8.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 25, 2025
CVE-2025-49416 on NVD →
FW Gallery <= 8.0.0 - Unauthenticated Arbitrary File Deletion
critical
The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.1
- Affected:
- up to 8.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 10, 2025
CVE-2025-49415 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database