
Cloud Vulnerability DB
A community-led vulnerabilities database
The Envira Gallery Plugin for WordPress (versions up to 1.12.0) contains a vulnerability related to unauthorized modification of data. The issue was discovered in November 2025 and was assigned the identifier CVE-2025-12377 (NVD Database, Red Hat Portal).
The vulnerability exists in the Gallery Plugin's permission handling mechanism, specifically affecting the Envira Photo Gallery functionality. The issue was addressed in version 1.12.1 by adding post type meta capability checks for better compatibility (WordPress Changelog).
The vulnerability could allow attackers to modify gallery data without proper authorization, potentially leading to unauthorized changes in WordPress gallery content (Red Hat Portal).
The vulnerability has been patched in version 1.12.1 of the Envira Gallery Plugin. Users are advised to update to this version which implements proper post type meta capability checks (WordPress Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."