Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Private Post Title and Excerpt Disclosure via gallery_data REST Field
- ID
- WPSEC-2026-0682
- Plugin
- Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More (envira-gallery-lite)
- Affected
- all versions before 1.16.2
- Remediation
- Update to 1.16.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Envira Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The Envira Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.1. The update callback of the gallery_data REST field accepted any post ID as a gallery image without checking that the user was allowed to use it, and stored that post's title and excerpt in the gallery, from where they are returned in the REST response. This makes it possible for authenticated attackers with gallery access, which contributors have by default, to read the titles and excerpts of private, draft and password-protected posts they cannot otherwise read.
References
- https://wpsec.com/vuln/WPSEC-2026-0682/
- https://plugins.svn.wordpress.org/envira-gallery-lite/tags/1.16.2/
- https://wordpress.org/plugins/envira-gallery-lite/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS