Impact
Unauthenticated broken access control exists in Envira Photo Gallery versions 1.12.5 and earlier, allowing any visitor to access protected galleries or photo metadata without authentication. The flaw is a missing authorization check, as identified by CWE‑862.
Affected Systems
The affected product is the Envira Photo Gallery plugin for WordPress, version 1.12.5 and earlier, distributed by Awesomemotive.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity; the EPSS score of <1% suggests low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this vulnerability through the WordPress site’s web interface, without authentication, to bypass access controls and view private gallery content. The likely attack vector is through the gallery URLs accessed via the site’s public webpages.
OpenCVE Enrichment