CVE-2026-81653
NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR
CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
| Vendor | unknown |
| Product | photo gallery, sliders, proofing and themes |
| Published | Sep 20, 2026 |
| Last Updated | Sep 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown photo gallery, sliders, proofing and themes
Be the first to know when new medium vulnerabilities affecting unknown photo gallery, sliders, proofing and themes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Photo Gallery, Sliders, Proofing and Themes
0 < 4.5.0
References
Credits
Erwan LR (WPScan) WPScan