Impact
The vulnerability is an IDOR in the NextGEN Gallery WordPress plugin that lets users with the Contributor role and higher retrieve metadata for any image, including EXIF data, checksums and internal identifiers, by bypassing ownership checks. This disclosure can expose camera details, timestamps and information that the plugin reserves for administrators, leading to data exposure. The flaw is a lack of authorization checks when serving image metadata, enabling unauthorized read access to sensitive descriptive data.
Affected Systems
The flaw affects the NextGEN Gallery WordPress plugin, specifically all releases prior to version 4.5.0. Deployments on WordPress sites using this plugin, regardless of the hosting environment, are vulnerable if they run an affected version.
Risk and Exploitability
While no EPSS score or KEV listing is available, the vulnerability can be exploited by any Contributor or higher role through normal API or URL calls, without additional credentials or network access. Attackers can target arbitrary image IDs and obtain confidential metadata, potentially aiding further reconnaissance. The lack of authentication gating results in moderate to high confidentiality risk for sites with sensitive visual content.
OpenCVE Enrichment