CVE-2025-13891 Details
Description
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endpoint verifies user capabilities (Author+ with upload_files and edit_posts permissions), it fails to validate that user-supplied directory paths reside within safe directories. This makes it possible for authenticated attackers, with Author-level access and above, to enumerate arbitrary directories on the server via the modula_list_folders endpoint.
A path traversal vulnerability has been identified in the Image Gallery – Photo Grid & Video Gallery plugin for WordPress, affecting all versions through 2.13.3. The vulnerability arises from the modula_list_folders AJAX endpoint, which lacks adequate path validation and base directory restrictions. Although the endpoint checks user capabilities for authors and above with upload_files and edit_posts permissions, it fails to ensure that user-supplied directory paths are within safe directories. This oversight allows authenticated attackers with author-level access or higher to enumerate arbitrary directories on the server via the modula_list_folders endpoint.
Users are advised to update the Image Gallery – Photo Grid & Video Gallery plugin to version 2.13.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 12, 2025CISA-ADP
Assessed Dec 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WPChill Modula | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 12, 2025 | New CVE Received | [email protected] |
Volerion