Impact
The Realwebcare Image Gallery – Responsive Photo Gallery plugin suffers from a missing authorization flaw (CWE-862). Because the plugin does not enforce proper access checks, users lacking legitimate privileges can view, edit or delete gallery items. This allows unauthorized manipulation of media content and potential exposure of sensitive images or alterations to site presentation, constituting a moderate confidentiality and integrity risk.
Affected Systems
WordPress sites that have installed Realwebcare Image Gallery – Responsive Photo Gallery versions from the very first release through 1.0.5 are affected. Any system running those plugin versions, regardless of WordPress version, is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity. An EPSS score of less than 1% indicates a low probability that this weakness will be actively exploited. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers are likely to exploit the flaw via web-based interactions with the plugin’s endpoints, potentially requiring only a low‑skill web attack or an authenticated but not sufficiently privileged user account.
OpenCVE Enrichment
EUVD