Description
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
Published: 2026-09-20
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Update
AI Analysis

Impact

The WordPress plugin lacks a check for the required options capability when a user attempts to save changes to image sizing settings. Consequently, a user who is only granted the gallery‑management capability—often assigned by site administrators to contributors or other lower‑privilege roles—can modify settings that affect the entire site’s image handling. This flaw enables a single authenticated user with limited rights to alter a global configuration that might influence how images are stored or displayed across the site.

Affected Systems

All releases of the Photo Gallery, Sliders, Proofing and Themes WordPress plugin before version 4.5.0 are affected. The vulnerability exists regardless of the WordPress installation hosting the plugin.

Risk and Exploitability

The flaw can be exploited by any authenticated user who has gallery‑management privileges, which many sites grant to contributors or intermediate roles. The CVSS score of 3.1 indicates low severity, and the EPSS score of < 1% suggests a low but measurable probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Because the flaw enables a low‑privilege user to change site‑wide image settings, the primary impact is a limited form of privilege escalation, where the attacker gains authority to alter global configuration instead of executing arbitrary code or achieving full system takeover.

Generated by OpenCVE AI on September 20, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the plugin to version 4.5.0 or later, which enforces proper capability checks for image settings.
  • Revoke the gallery‑management capability from users who should not modify site‑wide settings, limiting them to lower‑privilege roles.
  • Enable logging or monitoring for changes to image settings, and investigate any unauthorized alterations.
  • If an immediate update is not feasible, temporarily disable the gallery‑management role’s ability to edit image sizing settings via a custom role filter or by removing the capability from that role.

Generated by OpenCVE AI on September 20, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions nextgen Gallery
Vendors & Products Wordpress-extensions
Wordpress-extensions nextgen Gallery

Sun, 20 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
Title NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update
References

Subscriptions

Wordpress-extensions Nextgen Gallery
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:48:37.707Z

Reserved: 2026-08-27T09:27:38.744Z

Link: CVE-2026-81654

cve-icon Vulnrichment

Updated: 2026-09-20T13:48:27.599Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:49.997

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-81654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:48Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key