The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to view, create, modify, clone, delete, and reassign ownership of galleries created by other users, including administrators.
We have discovered 7,992 live websites that are affected by CVE-2025-15466.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 7,992 live websites (85% of Final Tiles Grid Gallery Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 46 versions ( 96% of all versions) |
| 1,745 websites | |
| 1,029 websites | |
| 585 websites | |
| 534 websites | |
| 418 websites | |
| 394 websites | |
| 318 websites | |
| 306 websites | |
| 182 websites | |
| 154 websites |
| .com | 3,011 websites |
| .de | 583 websites |
| .it | 349 websites |
| .org | 343 websites |
| .pl | 305 websites |
| .co.uk | 287 websites |
| .nl | 273 websites |
| .ru | 258 websites |
| .fr | 252 websites |
| .net | 137 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | **,*** | ||
| ****.ru | **,*** | ||
| ********.***.br | **,*** | ||
| **************.pl | ***,*** | ||
| ******************.org | ***,*** | ||
| **************.com | ***,*** | ||
| **********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ******.cz | ***,*** | ||
| ****.com | ***,*** |
FAQ