Impact
Envira Gallery for WordPress lacks an authorization check on its gallery‑conversion REST route, enabling any user with contributor level access to submit a post name and create or publish gallery content that the plugin otherwise restricts. This flaw allows attackers to bypass the intended creation constraints of the plugin, potentially flooding the site with unauthorized galleries. The weakness is a direct lack of proper access control for a privileged operation.
Affected Systems
The vulnerability affects the Envira Gallery plugin for WordPress in all releases prior to version 1.16.2. Users running any older build on a WordPress installation are at risk. The plugin’s REST endpoint used for gallery conversion is the entry point.
Risk and Exploitability
The report does not provide a CVSS score or EPSS value, and the vulnerability is not listed in the CISA KEV catalog. However, the missing authorization check represents a high‑impact flaw, as it grants contributors capabilities beyond their intended scope. Likely attack vectors involve authenticated HTTP requests to the plugin’s REST API; an attacker with contributor privileges can exploit the flaw remotely by sending a crafted POST to the conversion route. While the exploitation probability is unknown, the potential impact on integrity and availability is significant.
OpenCVE Enrichment