
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14170 is a Missing Authorization vulnerability in the Vimeo SimpleGallery plugin for WordPress, affecting all versions up to and including 0.2. The flaw allows authenticated attackers with Subscriber-level access or higher to modify arbitrary plugin settings by exploiting missing authorization checks on the vimeogallery_admin function hooked to admin_menu. It was published on December 12, 2025, and assigned by Wordfence. The CVSS v3.1 base score is 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). The vimeogallery_admin function, registered via the WordPress admin_menu hook, does not perform capability checks before processing requests, allowing any authenticated user — regardless of role — to submit requests with the action parameter to alter plugin settings. Exploitation requires only a valid WordPress account (Subscriber or above) and network access to the target site. The vulnerable code is visible in the plugin source at line 22 of vimeo_simplegallery.php (Wordfence, WordPress Trac).
Successful exploitation allows authenticated low-privileged users to modify arbitrary Vimeo SimpleGallery plugin settings, compromising the integrity of the WordPress site's gallery configuration. While confidentiality and availability are not directly impacted, unauthorized settings changes could be leveraged to inject malicious content or disrupt gallery functionality. The scope is limited to the plugin's configuration, but on sites where gallery content is user-facing, this could facilitate content manipulation or social engineering attacks (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14170. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access, further limiting the attack surface (Feedly).
/wp-content/plugins/vimeo-simplegallery/ for plugin presence.vimeogallery_admin function, including the desired action parameter value to modify plugin settings.page=vimeogallery or similar admin menu slugs).wp_options) for Vimeo SimpleGallery entries, particularly from non-administrator user accounts.vimeo_simplegallery.php or related plugin files.As of the disclosure date, no patched version of the Vimeo SimpleGallery plugin has been released; all versions up to and including 0.2 are affected. Site administrators should consider deactivating and removing the plugin until a fix is available. As a workaround, restrict user registration or limit Subscriber-level accounts on the WordPress site to reduce the attack surface. Monitor the WordPress plugin repository for an updated version that implements proper capability checks (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."