Impact
The WordPress plugin lacks a check for the required options capability when a user attempts to save changes to image sizing settings. Consequently, a user who is only granted the gallery‑management capability—often assigned by site administrators to contributors or other lower‑privilege roles—can modify settings that affect the entire site’s image handling. This flaw enables a single authenticated user with limited rights to alter a global configuration that might influence how images are stored or displayed across the site.
Affected Systems
All releases of the Photo Gallery, Sliders, Proofing and Themes WordPress plugin before version 4.5.0 are affected. The vulnerability exists regardless of the WordPress installation hosting the plugin.
Risk and Exploitability
The flaw can be exploited by any authenticated user who has gallery‑management privileges, which many sites grant to contributors or intermediate roles. The CVSS score of 3.1 indicates low severity, and the EPSS score of < 1% suggests a low but measurable probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Because the flaw enables a low‑privilege user to change site‑wide image settings, the primary impact is a limited form of privilege escalation, where the attacker gains authority to alter global configuration instead of executing arbitrary code or achieving full system takeover.
OpenCVE Enrichment