Impact
The vulnerability is an insecure direct object reference that allows any authenticated user who has been assigned gallery‑management privileges to delete, copy, or re‑tag images that belong to galleries owned by other users. Because the plugin does not verify gallery ownership before performing these actions, an attacker with such privileges could permanently remove or modify content, disrupt artistic or business assets, and potentially undermine credibility if key imagery is lost.
Affected Systems
The issue affects versions of the Photo Gallery, Sliders, Proofing and Themes WordPress plugin that are earlier than 4.5.0. These include all releases of the plugin labeled as nextGEN Gallery or equivalent across the Photo Gallery, Sliders, Proofing product line. No specific vendor name is listed; the plugin is distributed under the "Unknown:Photo Gallery, Sliders, Proofing" label.
Risk and Exploitability
The exploit requires legitimate credentials to a role that includes gallery‑management permissions, implying that the attacker must first broaden access or compromise an administrator account. The CVSS score of 4.2 indicates a low severity, and the EPSS score of <1% indicates a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, indicating that known active exploitation at this time is not documented. Nevertheless, the ability to delete or otherwise manipulate user content in an authenticated context suggests potential impact for affected sites that rely on the integrity of their image repositories.
OpenCVE Enrichment