{
 "id": "WPSEC-2026-0682",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0682/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0682/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0682/index.md",
 "title": "Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Private Post Title and Excerpt Disclosure via gallery_data REST Field",
 "description": "The Envira Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.1. The update callback of the gallery_data REST field accepted any post ID as a gallery image without checking that the user was allowed to use it, and stored that post's title and excerpt in the gallery, from where they are returned in the REST response. This makes it possible for authenticated attackers with gallery access, which contributors have by default, to read the titles and excerpts of private, draft and password-protected posts they cannot otherwise read.",
 "plugin": {
  "slug": "envira-gallery-lite",
  "name": "Envira Gallery",
  "full_name": "Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More",
  "wordpress_org": "https://wordpress.org/plugins/envira-gallery-lite/",
  "advisories_url": "https://wpsec.com/vuln/plugin/envira-gallery-lite/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/envira-gallery-lite"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.16.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.16.2"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.16.2",
 "remediation": "Update to 1.16.2 or later.",
 "fix_released": "2026-10-07T21:32:23+00:00",
 "published": "2026-10-08T21:46:21+00:00",
 "updated": "2026-10-08T07:40:42.574255+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0682/",
  "https://plugins.svn.wordpress.org/envira-gallery-lite/tags/1.16.2/",
  "https://wordpress.org/plugins/envira-gallery-lite/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/envira-gallery-lite",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}