๐Ÿ” CVE Alert

CVE-2026-104682

UNKNOWN 0.0

Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.

Vendor unknown
Product envira gallery
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown envira gallery

Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Envira Gallery
0 < 1.16.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/faaa0c75-64d7-4e92-99a6-e60805d2080b/

Credits

Karthik Ramakrishnan WPScan