Vulnerabilities / Envira Gallery / WPSEC-2026-0681
Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Sensitive Information Exposure of Private Galleries via Gallery Shortcode
Medium 4.3
CWE-639Fixed in 1.16.2
- ID
- WPSEC-2026-0681
- Plugin
- Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More (envira-gallery-lite)
- Affected
- all versions before 1.16.2
- Remediation
- Update to 1.16.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Envira Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The Envira Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.1. The envira-gallery shortcode rendered any gallery by ID or slug, and an admin AJAX gallery-list handler returned any gallery's title, slug and first image, without checking whether the user may view the gallery. This makes it possible for authenticated attackers with contributor-level access and above to view the contents of other users' private, draft and pending galleries.
References
- https://wpsec.com/vuln/WPSEC-2026-0681/
- https://plugins.svn.wordpress.org/envira-gallery-lite/tags/1.16.2/
- https://wordpress.org/plugins/envira-gallery-lite/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS