plugin

Fw Gallery Vulnerabilities

3 known security issues reported for the Fw Gallery WordPress plugin. Most recent disclosed Jun 30, 2025.

2 critical 1 high

Running Fw Gallery on your site? Check whether your installed version is affected.

Scan your site free

FW Gallery <= 8.0.0 - Unauthenticated Arbitrary File Upload

critical

The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers to upload arbitrary...

CVSS:
9.8
Affected:
up to 8.0.0
Fix:
No patched version reported
Disclosed:
Jun 30, 2025

CVE-2025-49414 on NVD →

FW Gallery <= 8.0.0 - Unauthenticated Local File Inclusion

high

The FW Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...

CVSS:
8.1
Affected:
up to 8.0.0
Fix:
No patched version reported
Disclosed:
Jun 25, 2025

CVE-2025-49416 on NVD →

FW Gallery <= 8.0.0 - Unauthenticated Arbitrary File Deletion

critical

The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 8.0.0. This makes it possible for unauthenticated attackers...

CVSS:
9.1
Affected:
up to 8.0.0
Fix:
No patched version reported
Disclosed:
Jun 10, 2025

CVE-2025-49415 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database