CVE-2026-25375: WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25375?
CVE-2026-25375 has been classified as a medium severity vulnerability due to its potential impact on user data and site integrity.
How do I fix CVE-2026-25375?
To fix CVE-2026-25375, update the WordPress Image Photo Gallery Final Tiles Grid plugin to version 3.6.11 or later.
What causes CVE-2026-25375?
CVE-2026-25375 is caused by broken access control settings that allow unauthorized users to exploit incorrectly configured security levels.
Which versions of the plugin are affected by CVE-2026-25375?
CVE-2026-25375 affects versions of the WordPress Image Photo Gallery Final Tiles Grid plugin up to and including version 3.6.10.
Can CVE-2026-25375 lead to data breaches?
Yes, CVE-2026-25375 can potentially lead to data breaches if unauthorized users gain access to restricted resources.