CVE-2025-49394: WordPress Image Gallery block – Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication vulnerability
Missing Authorization vulnerability in bPlugins Image Gallery block – Create and display photo gallery/photo album. 3d-image-gallery allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Image Gallery block – Create and display photo gallery/photo album.: from n/a through <= 1.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49394?
CVE-2025-49394 is considered a high severity vulnerability due to missing authorization checks.
How do I fix CVE-2025-49394?
To fix CVE-2025-49394, update the bPlugins Image Gallery to version 1.0.8 or later.
What versions are affected by CVE-2025-49394?
CVE-2025-49394 affects bPlugins Image Gallery and WordPress Image Gallery versions up to 1.0.7.
What type of vulnerability is CVE-2025-49394?
CVE-2025-49394 is a missing authorization vulnerability that allows access to restricted functionality.
Which software components are impacted by CVE-2025-49394?
CVE-2025-49394 impacts the Image Gallery block, which includes photo gallery and photo album functionalities.