Description
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to other users. The disclosed data includes the image's stored EXIF subset, covering camera make and model and capture timestamp, along with internal checksums and identifiers that the Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0's own capability-gated read path reserves to administrators.
Published: 2026-09-20
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is an IDOR (CWE-639) in the Photo Gallery, Sliders, Proofing and Themes WordPress plugin that allows any user with a Contributor role or higher to retrieve the stored EXIF metadata for any image on the site, including camera make and model, capture timestamp, and internal identifiers reserved for administrators, thus exposing sensitive information.

Affected Systems

The flaw affects the Photo Gallery, Sliders, Proofing and Themes plugin across all releases before version 4.5.0. Any WordPress installation that uses an affected version of this plugin, regardless of the hosting environment, is vulnerable.

Risk and Exploitability

The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in KEV. Based on the description, it is inferred that an attacker with a Contributor or higher role could target arbitrary image IDs to retrieve metadata, exposing sensitive information. The CVSS score of 2.7 categorizes the issue as low severity.

Generated by OpenCVE AI on September 20, 2026 at 18:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Photo Gallery, Sliders, Proofing and Themes plugin to version 4.5.0 or later.
  • Restrict Contributor privileges if they are not needed.
  • Monitor for unexpected metadata requests in case the IDOR remains present after upgrade.

Generated by OpenCVE AI on September 20, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions nextgen Gallery
Vendors & Products Wordpress-extensions
Wordpress-extensions nextgen Gallery

Sun, 20 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285
CWE-639

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to other users. The disclosed data includes the image's stored EXIF subset, covering camera make and model and capture timestamp, along with internal checksums and identifiers that the Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0's own capability-gated read path reserves to administrators.
Title NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR
References

Subscriptions

Wordpress-extensions Nextgen Gallery
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:48:07.751Z

Reserved: 2026-08-27T09:27:34.936Z

Link: CVE-2026-81652

cve-icon Vulnrichment

Updated: 2026-09-20T13:47:56.662Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:49.803

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-81652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:52Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key