Vulnerabilities / Envira Gallery / WPSEC-2026-0682

Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Private Post Title and Excerpt Disclosure via gallery_data REST Field

Medium 4.3 CWE-639Fixed in 1.16.2
ID
WPSEC-2026-0682
Plugin
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More (envira-gallery-lite)
Affected
all versions before 1.16.2
Remediation
Update to 1.16.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Envira Gallery on WPSec AttackSurface
Fix released
Published

Description

The Envira Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.1. The update callback of the gallery_data REST field accepted any post ID as a gallery image without checking that the user was allowed to use it, and stored that post's title and excerpt in the gallery, from where they are returned in the REST response. This makes it possible for authenticated attackers with gallery access, which contributors have by default, to read the titles and excerpts of private, draft and password-protected posts they cannot otherwise read.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0