CVE-2025-13543
HIGHPostGallery plugin <1.12.5 - File Upload
Title source: llmDescription
The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Exploits (2)
Scores
CVSS v3
8.8
EPSS
0.0014
EPSS Percentile
33.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
rtowebsites/PostGallery
< 1.12.5
Published
Dec 04, 2025
Tracked Since
Feb 18, 2026