CVE-2025-13603 PUBLISHED

WP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation

Assigner: Wordfence
Reserved: 24.11.2025 Published: 19.02.2026 Updated: 19.02.2026

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary content, which can lead to arbitrary file read on the server under certain configurations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor husainali52
Product WP AUDIO GALLERY
Versions Default: unaffected
  • affected from * to 2.0 (incl.)

Credits

  • Muhammad Yudha - DJ finder

References

Problem Types

  • CWE-862 Missing Authorization CWE