CVE-2025-13603Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary content, which can lead to arbitrary file read on the server under certain configurations.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2Technical Details · 2026-02-19: 202-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVETodo@CveTodo
    Disclosure

    CVE-2025-13603 pertains to a critical security flaw in the **WP AUDIO GALLERY** plugin for WordPress, affecting all versions up to 2.0. The vulnerability arises from insufficient capability checks and the absence of nonce verification in the `wpag_htaccess_callback` function. This flaw allows authenticated attackers with at least subscriber-level access to overwrite the site's `.htaccess` file with arbitrary content, potentially leading to arbitrary file reads under certain server configurations. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-13603

    Post summary

    The post announces CVE-2025-13603, describing how subscriber-level users can overwrite the site's .htaccess file via WP AUDIO GALLERY, but provides no proof of concept, exploit code, or patch information.

    0000038
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13603 The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient cap… https://www.cve.org/CVERecord?id=CVE-2025-13603

    Post summary

    The tweet announces CVE-2025-13603 as a vulnerability in WP Audio Gallery allowing unauthorized arbitrary file read up to version 2.0, without mentioning any PoC, exploit, or patch details.

    00000138
    56.4K followersView on X

Explore more