Description
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
Published: 2026-09-20
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated arbitrary image deletion, copy, and re‑tagging via IDOR
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an insecure direct object reference that allows any authenticated user who has been assigned gallery‑management privileges to delete, copy, or re‑tag images that belong to galleries owned by other users. Because the plugin does not verify gallery ownership before performing these actions, an attacker with such privileges could permanently remove or modify content, disrupt artistic or business assets, and potentially undermine credibility if key imagery is lost.

Affected Systems

The issue affects versions of the Photo Gallery, Sliders, Proofing and Themes WordPress plugin that are earlier than 4.5.0. These include all releases of the plugin labeled as nextGEN Gallery or equivalent across the Photo Gallery, Sliders, Proofing product line. No specific vendor name is listed; the plugin is distributed under the "Unknown:Photo Gallery, Sliders, Proofing" label.

Risk and Exploitability

The exploit requires legitimate credentials to a role that includes gallery‑management permissions, implying that the attacker must first broaden access or compromise an administrator account. The CVSS score of 4.2 indicates a low severity, and the EPSS score of <1% indicates a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, indicating that known active exploitation at this time is not documented. Nevertheless, the ability to delete or otherwise manipulate user content in an authenticated context suggests potential impact for affected sites that rely on the integrity of their image repositories.

Generated by OpenCVE AI on September 20, 2026 at 15:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest version of the Photo Gallery, Sliders, Proofing and Themes WordPress plugin, 4.5.0 or newer, to eliminate the IDOR flaw.
  • If an upgrade is not feasible, limit the gallery‑management capability to highly trusted administrator roles and remove the ability to delete, copy, or re‑tag images from lower‑privilege users.
  • Monitor site activity logs for unusual image deletion or copy actions, and consider temporarily disabling these functions until a permanent fix is available.

Generated by OpenCVE AI on September 20, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions nextgen Gallery
Vendors & Products Wordpress-extensions
Wordpress-extensions nextgen Gallery

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
Title NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR
References

Subscriptions

Wordpress-extensions Nextgen Gallery
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:48:45.933Z

Reserved: 2026-08-27T09:27:36.944Z

Link: CVE-2026-81653

cve-icon Vulnrichment

Updated: 2026-09-20T13:48:12.446Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:49.900

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-81653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:50Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key