
CVE-2025-13603 pertains to a critical security flaw in the **WP AUDIO GALLERY** plugin for WordPress, affecting all versions up to 2.0. The vulnerability arises from insufficient capability checks and the absence of nonce verification in the `wpag_htaccess_callback` function. This flaw allows authenticated attackers with at least subscriber-level access to overwrite the site's `.htaccess` file with arbitrary content, potentially leading to arbitrary file reads under certain server configurations. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-13603
Post summary
The post announces CVE-2025-13603, describing how subscriber-level users can overwrite the site's .htaccess file via WP AUDIO GALLERY, but provides no proof of concept, exploit code, or patch information.

