# CVE-2026-25345

## Summary

- **CVE ID:** CVE-2026-25345
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1284
- **Published:** Mar 25, 2026
- **Last Modified:** Apr 28, 2026

## Description

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.

## Affected Products

- GalleryCreator — SimpLy Gallery (n/a)
- GalleryCreator — SimpLy Gallery (0)

## References

- [CNA](https://patchstack.com/database/Wordpress/Plugin/simply-gallery-block/vulnerability/wordpress-simply-gallery-plugin-3-3-2-arbitrary-code-execution-vulnerability?_s_id=cve)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._