CVE-2025-13645: Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajaxunzipfile' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13645?
CVE-2025-13645 is a high severity vulnerability due to its potential for arbitrary file deletion and exploitation by authenticated attackers.
How do I fix CVE-2025-13645?
To fix CVE-2025-13645, update the Modula Image Gallery plugin to version 2.13.3 or later where the issue has been addressed.
Who is affected by CVE-2025-13645?
CVE-2025-13645 affects all users of the Modula Image Gallery plugin versions 2.13.1 to 2.13.2 with Author-level access or higher.
What kind of attacks can be performed using CVE-2025-13645?
Using CVE-2025-13645, an authenticated attacker can exploit insufficient file path validation to delete arbitrary files from the server.
When was CVE-2025-13645 disclosed?
CVE-2025-13645 was disclosed as a vulnerability impacting versions 2.13.1 to 2.13.2 of the Modula Image Gallery plugin.