Impact
An authenticated user granted gallery‑management permissions can overwrite any gallery’s stored settings, including its filesystem path, because the plugin fails to verify ownership upon save. This unauthorized configuration modification allows the attacker to redirect gallery assets to arbitrary locations, potentially replacing legitimate media with malicious files or exposing sensitive content, thereby compromising data confidentiality and integrity. The flaw manifests as an Insecure Direct Object Reference (IDOR).
Affected Systems
The vulnerability targets the WordPress plugin Photo Gallery, Sliders, Proofing and Themes in any installation running a version prior to 4.5.0. No specific vendor or partner names are listed beyond the plugin itself; any site using the plugin before this release is susceptible.
Risk and Exploitability
The CVSS score is 3.1, and the EPSS score is below 1%, indicating a low likelihood of exploitation. The flaw requires an authenticated user with the gallery‑management capability to exploit, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the gallery‑management interface where ownership checks are omitted. While no remote code execution is possible, the ability to manipulate filesystem paths could enable data exfiltration or serve as a foothold for further attacks if an attacker controls a gallery.
OpenCVE Enrichment