Impact
The vulnerability is an Insecure Direct Object Reference that allows an attacker to bypass authorization controls by manipulating user‑controlled keys. By crafting requests with specific identifiers, an attacker can access, view, or modify gallery content that should be restricted, effectively gaining unauthorized access to protected data. This is a privilege escalation issue where the integrity and confidentiality of the gallery content can be compromised.
Affected Systems
The affected product is the WP Chill Image Photo Gallery Final Tiles Grid plugin. Versions from the initial release through 3.6.11 are vulnerable. Users running the plugin on WordPress sites should verify that they are on a newer version before 3.6.11.
Risk and Exploitability
The CVSS score of 2.7 denotes a low severity, and the EPSS of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker likely needs only web access to the target site and knowledge of the gallery URL patterns to exploit the IDOR; in many cases, the plugin does not enforce strict authentication for gallery objects, making the attack vector accessible from the public web interface.
OpenCVE Enrichment