CVE-2025-13543 - PostGallery <= 1.12.5 - authenticated (subscriber+) arbitrary file upload

CVE-2025-13543 - PostGallery <= 1.12.5 - authenticated (subscriber+) arbitrary file upload

CVE ID : CVE-2025-13543 Published : Dec. 4, 2025, 8:27 p.m. | 22 minutes ago Description : The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Dec. 4, 2025
Affected Product: WordPress
Impact: remote code execution

Source: Telegram CVE Monitor