Description
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
Published: 2026-10-11
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
Title Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:42:52.997Z

Reserved: 2026-10-02T08:22:34.360Z

Link: CVE-2026-104682

cve-icon Vulnrichment

Updated: 2026-10-11T11:28:37.711Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:22.763

Modified: 2026-10-11T12:16:51.813

Link: CVE-2026-104682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:30:05Z

Weaknesses