Sceawere

Vulnerability Detail

CVE-2026-104645UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insecure Authorization in Final Tiles Grid

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
8h ago
Vendor
Unknown
Product
Image Photo Gallery Final Tiles Grid
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-08T06:16:38.747Z",
  "pubdate": "2026-10-08T06:16:38.747Z",
  "executiveSummary": "The Image Photo Gallery Final Tiles Grid WordPress plugin prior to version 3.6.14 contains multiple authorization bypass vulnerabilities. These flaws reside within various gallery and image management functions that fail to properly validate user permissions or correctly verify object ownership before executing administrative actions.\nThe vulnerability allows authenticated users with contributor-level privileges or higher to perform unauthorized operations, including cloning, modifying, and reordering galleries or images that belong to other users. Furthermore, attackers can inject plugin-specific metadata into arbitrary posts they do not own, potentially leading to unauthorized data modification or administrative interference within the WordPress site.\nThis vulnerability is classified as an Improper Authorization flaw, posing a significant risk to data integrity and content management security. Because the plugin logic checks ownership against inconsistent objects or neglects authorization checks entirely, the security boundary between different user roles and resource owners is effectively eliminated. Exploitation does not require elevated administrative privileges, making it accessible to any registered contributor account. Organizations relying on this plugin should prioritize immediate remediation to prevent unauthorized gallery manipulation and metadata injection.",
  "technicalDetails": "The core issue is a failure in the plugin’s access control mechanism during the execution of AJAX actions and REST API handlers responsible for gallery and image management. The affected versions (prior to 3.6.14) lack consistent authorization checks for sensitive operations such as cloning, updating, and reordering resources.\nThe vulnerability manifests through two primary misconfigurations in the codebase: improper object verification and missing authorization checks. When a user initiates a request to modify a gallery or image, the plugin logic incorrectly validates ownership by checking against an unintended object or failing to trigger a privilege verification function entirely. Consequently, the server-side code processes the requested action regardless of the requester’s relationship to the target resource.\nThe attack flow proceeds as follows: First, an authenticated attacker identifies the ID of a target gallery or image owned by another user. Second, the attacker crafts a malicious request (often via POST) targeting the specific AJAX handler responsible for gallery manipulation. Because the plugin does not verify if the authenticated user is the legitimate owner or possesses appropriate administrative privileges, the underlying function executes the requested operation—such as duplicating a private gallery or reordering images within a gallery the attacker should not be able to view or manage.\nAdditionally, the vulnerability allows for arbitrary metadata injection. An attacker can manipulate request parameters to write plugin-specific metadata onto arbitrary posts. By exploiting this, an attacker can append or modify post meta data, which may alter the appearance of front-end galleries or potentially facilitate secondary attacks if the metadata is improperly handled by other components of the plugin or theme. The lack of proper nonce verification and capability checks ('manage_options' or equivalent) permits these actions to be performed by any contributor-level user.\nThe post-exploitation impact includes the loss of content confidentiality (via unauthorized viewing and cloning of galleries), unauthorized modification of site assets, and the degradation of data integrity through persistent metadata manipulation. The flaw is persistent, meaning the modifications remain effective until manually corrected by an administrator. Given that the plugin relies on client-side input for object targeting without secondary server-side validation, the software fails to maintain a secure 'Confused Deputy' posture in its administrative workflow."
}
CVE-2026-104645: Insecure Authorization in Final Tiles Grid (LOW Severity, CVSS: 2.7) | Sceawere