Impact
The Image Photo Gallery Final Tiles Grid WordPress plugin failed to verify user authorization on a range of gallery and image management actions, checking ownership against an incorrect object or omitting the check altogether. This flaw is an instance of Implicit Direct Object Reference (IDOR), allowing any authenticated contributor or higher role to clone galleries, modify and reorder images, and write the plugin’s metadata onto posts they do not own. The result is unauthorized alteration of the site’s visual content and potential defacement or privacy exposure.
Affected Systems
WordPress installations that have the Image Photo Gallery Final Tiles Grid plugin installed at a version earlier than 3.6.14 are susceptible. The flaw can be exploited by any user account with contributor or higher permissions on the host site.
Risk and Exploitability
Because the vulnerability requires an authenticated user with contributor privileges, the attack requires an existing login but no special technical skill. The absence of a CVSS or EPSS score suggests the risk is moderate to high in environments where contributors are numerous or have broad privileges, yet the exploitation probability is not quantified. The issue is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at the time of this analysis. Attackers would gain the ability to manipulate gallery content and non‑plugin post metadata, which could undermine site integrity and user trust.
OpenCVE Enrichment