CVE-2025-13603
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13603 is a Missing Authorization vulnerability in the WP AUDIO GALLERY plugin for WordPress that allows authenticated attackers to overwrite the site's .htaccess file with arbitrary content, potentially enabling arbitrary file read. All versions up to and including 2.0 are affected. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Wordfence).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). Specifically, the wpag_htaccess_callback function in the WP AUDIO GALLERY plugin lacks both sufficient capability checks and nonce verification, allowing any authenticated user with subscriber-level access or above to invoke it (Feedly). An attacker can send a crafted authenticated HTTP request to trigger this function and overwrite the server's .htaccess file with arbitrary content. Under certain Apache server configurations, a manipulated .htaccess can be used to expose or serve arbitrary files, leading to unauthorized file read (Wordfence).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges (subscriber-level) to overwrite the .htaccess file, which can result in high confidentiality, integrity, and availability impacts. Sensitive server-side files (e.g., configuration files, credentials) may be exposed through arbitrary file read, and the modification of .htaccess can disrupt site availability or redirect traffic. The scope is limited to the affected server, but the ability to read arbitrary files could facilitate lateral movement or credential harvesting (Feedly).

Exploitability

As of the available intelligence, no public proof-of-concept exploit code has been published and no in-the-wild exploitation has been observed (Feedly). The EPSS score is 0.04%, indicating a low current probability of exploitation. The vulnerability has been detected by Qualys (detection ID 530997) and is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, Qualys). Exploitation requires only a low-privilege authenticated account, which lowers the barrier for abuse if credentials are obtained.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP AUDIO GALLERY plugin version 2.0 or earlier using tools like WPScan or by inspecting plugin directories exposed via the target site.
  2. Obtain Authenticated Access: Register or obtain a subscriber-level (or higher) WordPress account on the target site.
  3. Craft Malicious Request: Prepare an authenticated HTTP POST request targeting the wpag_htaccess_callback AJAX action or equivalent endpoint, supplying arbitrary .htaccess content as the payload (e.g., enabling directory listing or aliasing sensitive file paths).
  4. Overwrite .htaccess: Submit the crafted request. Due to missing capability checks and absent nonce verification, the plugin writes the attacker-controlled content to the site's .htaccess file.
  5. Achieve Arbitrary File Read: With a modified .htaccess, leverage Apache directives (e.g., Options +Indexes, custom Alias or RewriteRule directives) to expose or serve arbitrary server files, then retrieve sensitive data via HTTP requests (Feedly, Wordfence).

Indicators of compromise

  • File System: Unexpected or unauthorized modifications to the .htaccess file in the WordPress root or subdirectories; unusual directives such as Options +Indexes, custom Alias, or RewriteRule entries pointing to sensitive paths.
  • Logs: WordPress access logs showing authenticated POST requests to AJAX endpoints (e.g., wp-admin/admin-ajax.php) with the wpag_htaccess_callback action from subscriber-level accounts; web server logs showing access to files outside the web root or unusual file paths being served.
  • Network: HTTP requests from low-privilege user sessions targeting admin AJAX endpoints with .htaccess-related parameters; subsequent requests fetching sensitive files (e.g., wp-config.php, /etc/passwd) via the web server.

Mitigation and workarounds

Users should immediately upgrade the WP AUDIO GALLERY plugin to a version above 2.0 once a patched release becomes available (Feedly). Until a patch is released, consider disabling or removing the plugin entirely. Additional mitigations include restricting subscriber-level account creation to trusted users, implementing file integrity monitoring on .htaccess files, and applying server-level controls to prevent web processes from modifying .htaccess (Feedly, Wordfence).

Community reactions

Wordfence included CVE-2025-13603 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable plugin vulnerability (Wordfence). Qualys added detection for this vulnerability in their March 2026 application security detections update (Qualys). No significant social media discussion or vendor statements beyond these security community acknowledgments have been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management