plugin

Vimeo Simplegallery Vulnerabilities

2 known security issues reported for the Vimeo Simplegallery WordPress plugin. Most recent disclosed Dec 12, 2025.

1 medium

Running Vimeo Simplegallery on your site? Check whether your installed version is affected.

Scan your site free

Vimeo SimpleGallery [vimeo-simplegallery] <= 0.2 (unfixed)

unknown

[en] The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber-level access an...

Affected:
up to 0.2
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-14170 on NVD →

Vimeo SimpleGallery <= 0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification

medium

The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber-level access and abo...

CVSS:
4.3
Affected:
up to 0.2
Fix:
No patched version reported
Disclosed:
Dec 11, 2025

CVE-2025-14170 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database