๐Ÿ” CVE Alert

CVE-2026-104680

UNKNOWN 0.0

Envira Gallery < 1.16.2 - Multisite Subsite Admin+ Arbitrary Plugin Installation via Onboarding Wizard

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin.

Vendor unknown
Product envira gallery
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown envira gallery

Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Envira Gallery
0 < 1.16.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/04e7dc2a-764e-4c0b-b929-d9f1881ef1ca/

Credits

Karthik Ramakrishnan WPScan