plugin

Wp Audio Gallery Vulnerabilities

4 known security issues reported for the Wp Audio Gallery WordPress plugin. Most recent disclosed Feb 19, 2026.

2 high

Running Wp Audio Gallery on your site? Check whether your installed version is affected.

Scan your site free

WP AUDIO GALLERY [wp-audio-gallery] <= 2.0 (unfixed)

unknown

[en] The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subsc...

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2025-13603 on NVD →

WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation

high

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber...

CVSS:
8.8
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2026

CVE-2025-13603 on NVD →

WP AUDIO GALLERY [wp-audio-gallery] <= 2.0 (unfixed + closed)

unknown

[en] The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter befor...

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-13322 on NVD →

WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter

high

The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter before pas...

CVSS:
8.1
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Nov 20, 2025

CVE-2025-13322 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database