CVE-2026-104682
Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
| Vendor | unknown |
| Product | envira gallery |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown envira gallery
Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Envira Gallery
0 < 1.16.2
References
Credits
Karthik Ramakrishnan WPScan