Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Gallery and Post Metadata Modification
Action: Patch Immediately
AI Analysis

Impact

The Image Photo Gallery Final Tiles Grid WordPress plugin failed to verify user authorization on a range of gallery and image management actions, checking ownership against an incorrect object or omitting the check altogether. This flaw is an instance of Implicit Direct Object Reference (IDOR), allowing any authenticated contributor or higher role to clone galleries, modify and reorder images, and write the plugin’s metadata onto posts they do not own. The result is unauthorized alteration of the site’s visual content and potential defacement or privacy exposure.

Affected Systems

WordPress installations that have the Image Photo Gallery Final Tiles Grid plugin installed at a version earlier than 3.6.14 are susceptible. The flaw can be exploited by any user account with contributor or higher permissions on the host site.

Risk and Exploitability

Because the vulnerability requires an authenticated user with contributor privileges, the attack requires an existing login but no special technical skill. The absence of a CVSS or EPSS score suggests the risk is moderate to high in environments where contributors are numerous or have broad privileges, yet the exploitation probability is not quantified. The issue is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at the time of this analysis. Attackers would gain the ability to manipulate gallery content and non‑plugin post metadata, which could undermine site integrity and user trust.

Generated by OpenCVE AI on October 8, 2026 at 07:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Image Photo Gallery Final Tiles Grid plugin to version 3.6.14 or newer.
  • Restrict contributor roles or adjust role permissions so that contributors cannot edit galleries or posts they do not own.
  • Regularly audit gallery and post metadata for unauthorized changes and monitor access logs for anomalous activity.

Generated by OpenCVE AI on October 8, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own.
Title Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Image Modification and Post Meta Update via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:05.702Z

Reserved: 2026-10-02T05:40:33.815Z

Link: CVE-2026-104645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:38.747

Modified: 2026-10-08T06:16:38.747

Link: CVE-2026-104645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key