WP AUDIO GALLERY [wp-audio-gallery] <= 2.0 (unfixed)
unknown
[en] The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subsc...
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2025-13603 on NVD →
WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation
high
The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber...
- CVSS:
- 8.8
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 18, 2026
CVE-2025-13603 on NVD →
WP AUDIO GALLERY [wp-audio-gallery] <= 2.0 (unfixed + closed)
unknown
[en] The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter befor...
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-13322 on NVD →
WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter
high
The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter before pas...
- CVSS:
- 8.1
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2025
CVE-2025-13322 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database