CVE-2026-104680 PUBLISHED

Envira Gallery < 1.16.2 - Multisite Subsite Admin+ Arbitrary Plugin Installation via Onboarding Wizard

Assigner: WPScan
Reserved: 02.10.2026 Published: 11.10.2026 Updated: 11.10.2026

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin.

Product Status

Vendor Unknown
Product Envira Gallery
Versions Default: unaffected
  • affected from 0 to 1.16.2 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE