Impact
The vulnerability is a missing authorization flaw (CWE-862) that allows an attacker to bypass configured security levels and gain unauthorized access to administrative functions within the WordPress Image Photo Gallery Final Tiles Grid plugin. This could enable the attacker to modify, delete, or view gallery settings and potentially compromise other stored data accessed through the plugin, thereby affecting the integrity and confidentiality of the gallery configuration for the affected installation.
Affected Systems
The vulnerability affects the WordPress Image Photo Gallery Final Tiles Grid plugin provided by WP Chill. All releases with a version number up to and including 3.6.11 are vulnerable. Versions 3.6.12 and newer are not affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate security impact. No EPSS data is available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so the likelihood of widespread exploitation remains uncertain. The likely attack vector is remote through the web interface, assuming the site provides administrative access to the plugin settings. Attackers with access to the vulnerable plugin’s administrative pages could exploit the lack of authorization checks to manipulate configuration or access restricted data.
OpenCVE Enrichment