ays-pro Vulnerabilities and Affected Products
Vulnerabilities associated with Photo Gallery by Ays – Responsive Image Gallery.
Products
Clear product- Poll Maker – Versus Polls, Anonymous Polls, Image Polls8 vulnerabilities
- Quiz Maker6 vulnerabilities
- Secure Copy Content Protection and Content Locking5 vulnerabilities
- Survey Maker5 vulnerabilities
- AI ChatBot with ChatGPT and Content Generator by AYS3 vulnerabilities
- Popup Box – Create Countdown, Coupon, Video, Contact Form Popups3 vulnerabilities
- popup_box3 vulnerabilities
- secure_copy_content_protection_and_content_locking3 vulnerabilities
- ai_chatbot_with_chatgpt2 vulnerabilities
- Chartify – WordPress Chart Plugin2 vulnerabilities
- poll_maker2 vulnerabilities
- quiz_maker2 vulnerabilities
- chartify1 vulnerability
- FAQ Builder AYS1 vulnerability
- Fox LMS – WordPress LMS Plugin1 vulnerability
- Image Slider by Ays- Responsive Slider and Carousel1 vulnerability
- Photo Gallery by Ays – Responsive Image Gallery1 vulnerability
- Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls1 vulnerability
- Quiz Maker by AYS1 vulnerability
- survey_maker1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-13685MEDIUM | Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk ActionsThe Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk operations (delete, publish, or unpublish galleries) via a forged request granted they can trick an administrator into performing an action such as clicking on a link. CWE-352Dec 2, 2025 | CVSS4.3v3.1 | EPSS0.157% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |