Impact
The plugin fails to enforce the configured access control levels, allowing any user to view or manipulate media and galleries that are meant to be private. This results in a direct compromise of confidentiality, exposing sensitive images and potentially revealing private content to the public.
Affected Systems
WordPress installations running the Image Photo Gallery Final Tiles Grid plugin from WP Chill, in any version up to and including 3.6.10, are affected until the vulnerability is remedied.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. Attackers can likely trigger the flaw by sending standard HTTP requests to the plugin’s endpoints without needing elevated privileges or host compromise; however, there are no known public exploits and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment