Description
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
Published: 2026-10-11
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: Authorization bypass allowing contributors to create and publish gallery posts
Action: Apply Patch
AI Analysis

Impact

Envira Gallery for WordPress lacks an authorization check on its gallery‑conversion REST route, enabling any user with contributor level access to submit a post name and create or publish gallery content that the plugin otherwise restricts. This flaw allows attackers to bypass the intended creation constraints of the plugin, potentially flooding the site with unauthorized galleries. The weakness is a direct lack of proper access control for a privileged operation.

Affected Systems

The vulnerability affects the Envira Gallery plugin for WordPress in all releases prior to version 1.16.2. Users running any older build on a WordPress installation are at risk. The plugin’s REST endpoint used for gallery conversion is the entry point.

Risk and Exploitability

The report does not provide a CVSS score or EPSS value, and the vulnerability is not listed in the CISA KEV catalog. However, the missing authorization check represents a high‑impact flaw, as it grants contributors capabilities beyond their intended scope. Likely attack vectors involve authenticated HTTP requests to the plugin’s REST API; an attacker with contributor privileges can exploit the flaw remotely by sending a crafted POST to the conversion route. While the exploitation probability is unknown, the potential impact on integrity and availability is significant.

Generated by OpenCVE AI on October 11, 2026 at 07:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Envira Gallery plugin to version 1.16.2 or later, which restores proper authorization checks on the conversion route.
  • If an upgrade cannot be applied immediately, block the gallery‑conversion REST endpoint for contributor roles using a security plugin or custom code that denies access based on role before executing the route.
  • Review contributed posts and delete any galleries created through the vulnerability, and audit contributor activity logs for suspicious changes.
  • Reassess contributor permissions and consider removing gallery‑creation capabilities from the contributor role until the plugin is updated.

Generated by OpenCVE AI on October 11, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
Title Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:42:52.997Z

Reserved: 2026-10-02T08:22:34.360Z

Link: CVE-2026-104682

cve-icon Vulnrichment

Updated: 2026-10-11T11:28:37.711Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:22.763

Modified: 2026-10-11T12:16:51.813

Link: CVE-2026-104682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:30:05Z

Weaknesses