---
id: CVE-2025-13322
title: >-
  The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file
  deletion due to insufficient file path validation in all versions up to, and
  including, 2.0
summary: >-
  The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file
  deletion due to insufficient file path validation in all versions up to, and
  including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler
  not prop…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-73
published: '2025-11-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13322'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-audio-gallery/tags/2.0/wp-audio-gallery.php#L150
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-audio-gallery/tags/2.0/wp-audio-gallery.php#L513
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-audio-gallery/tags/2.0/wp-audio-gallery.php#L607
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/101675ae-88cf-42fc-b9ea-5dd37cdf7464?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00629
epssPercentile: 0.48477
ingestedAt: '2026-10-08T10:28:19.724Z'
---

## Overview

The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter before passing them to `unlink()`. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when critical files like wp-config.php are deleted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
