CVE-2025-7641 | Assistant for NextGEN Gallery Plugin up to 1.0.0/1.0.9 on WordPress REST Endpoint control improper authorization (EUVD-2025-25004)
A vulnerability was found in Assistant for NextGEN Gallery Plugin up to 1.0.0/1.0.9 on WordPress. It has been classified as critical. This vulnerability affects unknown code of the file /wp-json/nextgenassistant/v1.0.0/control of the component REST Endpoint. The manipulation leads to improper authorization.
This vulnerability was named CVE-2025-7641. The attack can be initiated remotely. There is no exploit available.