Sceawere

Vulnerability Detail

CVE-2026-102399UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CSRF in Photo Gallery by Supsystic

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
supsystic
Product
Photo Gallery by Supsystic
Attack Type
CWE-352 Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-30T13:17:17.773Z",
  "pubdate": "2026-09-30T13:17:17.773Z",
  "executiveSummary": "The Photo Gallery by Supsystic plugin, in versions 1.21.0 and earlier, contains a critical Cross-Site Request Forgery (CSRF) vulnerability.\nThis vulnerability stems from the absence of proper nonce validation or state-changing request verification within the plugin's administrative actions.\nAn unauthenticated attacker can exploit this flaw by tricking an authenticated administrator into executing unauthorized actions via a crafted web page.\nThe impact includes unauthorized configuration changes, potential injection of malicious content, and other administrative modifications within the WordPress environment.\nThe vulnerability poses a significant risk to site integrity, as it allows attackers to bypass intended access controls by leveraging the authenticated session of an administrator.\nNo direct authentication is required from the attacker to initiate the attack; however, successful exploitation relies on the victim visiting a malicious link or interacting with compromised content while logged into the WordPress dashboard.",
  "technicalDetails": "The vulnerability is identified as a Cross-Site Request Forgery (CSRF) originating from inadequate implementation of security tokens within the Photo Gallery by Supsystic plugin codebase.\nSpecifically, the plugin fails to enforce nonce verification on sensitive administrative endpoints or AJAX action handlers, which are responsible for plugin configuration and data manipulation.\nIn the WordPress environment, nonces (numbers used once) are essential cryptographic tokens that ensure a request originated from the legitimate dashboard interface rather than an external, untrusted source.\nBecause the plugin omits these checks, any state-changing HTTP request (e.g., POST or GET) sent to the vulnerable endpoint will be processed by the server if the request is made by a user with an active administrative session.\nThe attack flow begins when an attacker prepares a malicious payload, typically embedded within an <img> tag, a hidden <iframe>, or a scripted form hosted on an external domain controlled by the adversary.\nThe attacker then lures an authenticated WordPress administrator to the malicious URL. When the victim's browser loads the crafted content, it automatically issues a background request to the vulnerable Photo Gallery by Supsystic plugin endpoint using the administrator's existing session cookies.\nBecause the server cannot differentiate between the administrator's intentional action and the attacker-initiated request, it executes the command with the full privileges of the administrator.\nThis can result in unauthorized changes to gallery settings, modification of plugin metadata, or the execution of other administrative functions available within the plugin's interface.\nThe scope of impact is limited to the functionality exposed by the vulnerable plugin; however, the lack of CSRF protection represents a fundamental breakdown in the application's request authentication flow.\nVersions 1.21.0 and below are confirmed as susceptible to this exploit due to the persistent absence of request validation logic across the plugin's administrative modules."
}
CVE-2026-102399: CSRF in Photo Gallery by Supsystic (MEDIUM Severity, CVSS: 5.4) | Sceawere