Vulnerabilities / Envira Gallery / WPSEC-2026-0681

Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Sensitive Information Exposure of Private Galleries via Gallery Shortcode

Medium 4.3 CWE-639Fixed in 1.16.2
ID
WPSEC-2026-0681
Plugin
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More (envira-gallery-lite)
Affected
all versions before 1.16.2
Remediation
Update to 1.16.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Envira Gallery on WPSec AttackSurface
Fix released
Published

Description

The Envira Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.1. The envira-gallery shortcode rendered any gallery by ID or slug, and an admin AJAX gallery-list handler returned any gallery's title, slug and first image, without checking whether the user may view the gallery. This makes it possible for authenticated attackers with contributor-level access and above to view the contents of other users' private, draft and pending galleries.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0