CVE-2025-13693

Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 6,997 live websites that are affected by CVE-2025-13693.

Run a Free Instant Scan




Affected Software

Product  Final Tiles Grid Gallery Lite
Category Wordpress Plugins
Vulnerable Domains6,997 live websites (74% of Final Tiles Grid Gallery Lite install base)
Vulnerable Versions
  • from 0 through 3.6.8
Vulnerable Versions Count45 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 21, 2025
  • Updated - Dec 22, 2025

Credits

  • Athiwat Tiprasaharn (finder)
  • Itthidej Aramsri (finder)
  • Powpy (finder)
  • Waris Damkham (finder)
  • Varakorn Chanthasri (finder)
  • Peerapat Samatathanyakorn (finder)

Website Distribution by Country

Number of websites using CVE-2025-13693
United States1,437 websites



Germany906 websites
France510 websites
Italy493 websites
Poland357 websites
GB349 websites
Russia304 websites
Netherlands256 websites
Spain167 websites
Switzerland131 websites

Website Distribution by TLD

Number of websites using CVE-2025-13693
.com2,598 websites
.de508 websites
.it325 websites
.org294 websites
.pl275 websites
.ru248 websites
.co.uk229 websites
.nl228 websites
.fr209 websites
.net118 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13693

Top websites that are affected by CVE-2025-13693. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.ru Russia**,***
********.***.br Brazil**,***
**************.pl Poland***,***
******************.org United States***,***
**************.com Belgium***,***
**********.com United States***,***
***********.com United States***,***
******.cz Czech Republic***,***
****.com United States***,***
************.***.uk GB***,***
See full domain list

FAQ

CVE-2025-13693 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Final Tiles Grid Gallery Lite
A total of 6,997 websites have been identified as vulnerable to CVE-2025-13693, based on global website indexing conducted by WebTechSurvey.
The Final Tiles Grid Gallery Lite is affected by the CVE-2025-13693 vulnerability.
Final Tiles Grid Gallery Lite versions up to and including 3.6.8 are vulnerable to CVE-2025-13693.