๐Ÿ” CVE Alert

CVE-2019-25149

HIGH 7.6

Gallery Images Ape <= 2.0.6 - Authenticated Plugin Deactivation

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site functionality or security.

CWE CWE-285
Vendor galleryape
Product gallery images ape
Published Jun 7, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for galleryape gallery images ape

Be the first to know when new high vulnerabilities affecting galleryape gallery images ape are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

galleryape / Gallery Images Ape
0 < 2.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/dfd6c2b8-b00c-49d1-930f-50397e742ac5?source=cve blog.nintechnet.com: https://blog.nintechnet.com/wordpress-ape-gallery-plugin-fixed-authenticated-arbitrary-plugin-deactivation-vulnerability/

Credits

Jerome Bruandet