Impact
The Meta‑box GalleryMeta WordPress plugin has a missing capability check on the custom post type ‘mb_gallery’ in all releases up to and including 3.0.1. This flaw allows authenticated users with Author privileges or higher to create and publish gallery posts without appropriate authorization. The weakness is classified as CWE‑862, an authorization failure due to a missing privilege check.
Affected Systems
Any WordPress site that has the Meta‑box GalleryMeta plugin installed and active at version 3.0.1 or earlier is vulnerable; the issue is independent of other plugins or themes.
Risk and Exploitability
The CVSS score of 4.3 reflects low‑to‑moderate severity, and the EPSS score of less than 1% indicates very rare exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated and possess at least Author role. No public exploit has been documented, and exploitation requires only the submission of gallery creation requests that bypass the missing capability check.
OpenCVE Enrichment