CVE-2026-104684 PUBLISHED

Envira Gallery < 1.16.2 - Author+ IDOR via Shortcode

Assigner: WPScan
Reserved: 02.10.2026 Published: 11.10.2026 Updated: 11.10.2026

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors.

Product Status

Vendor Unknown
Product Envira Gallery
Versions Default: unaffected
  • affected from 0 to 1.16.2 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE