๐Ÿ” CVE Alert

CVE-2026-104681

UNKNOWN 0.0

Envira Gallery < 1.16.2 - Author+ Non-Public Post Title and Excerpt Disclosure via Gallery REST Field

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.

Vendor unknown
Product envira gallery
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown envira gallery

Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Envira Gallery
0 < 1.16.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bc899a2c-4b79-42a3-a313-a9fa2c3709c7/

Credits

Karthik Ramakrishnan WPScan