CVE-2026-104682 PUBLISHED

Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route

Assigner: WPScan
Reserved: 02.10.2026 Published: 11.10.2026 Updated: 11.10.2026

The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.

Product Status

Vendor Unknown
Product Envira Gallery
Versions Default: unaffected
  • affected from 0 to 1.16.2 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE