CVE-2019-25149: Gallery Images Ape <= 2.0.6 - Authenticated Plugin Deactivation
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site functionality or security.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25149?
CVE-2019-25149 has a high severity rating as it allows authenticated attackers to deactivate critical plugins.
How do I fix CVE-2019-25149?
To fix CVE-2019-25149, update the Gallery Images Ape plugin to version 2.0.7 or later.
Who is affected by CVE-2019-25149?
CVE-2019-25149 affects all WordPress sites using the Gallery Images Ape plugin version 2.0.6 or earlier.
What type of vulnerability is CVE-2019-25149?
CVE-2019-25149 is an Arbitrary Plugin Deactivation vulnerability.
What can an attacker accomplish with CVE-2019-25149?
An attacker can deactivate any plugin on a vulnerable site, potentially compromising site functionality and security.