Sceawere

Vulnerability Detail

CVE-2026-104680UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Envira Gallery Improper Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
8h ago
Vendor
Unknown
Product
Envira Gallery
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-11T07:17:22.550Z",
  "pubdate": "2026-10-11T07:17:22.550Z",
  "executiveSummary": "The Envira Gallery WordPress plugin prior to version 1.16.2 contains a critical authorization vulnerability related to the handling of setup-wizard installation requests.\nThe vulnerability is categorized as an Improper Access Control issue, where the plugin fails to perform adequate capability checks before processing installation routines.\nThis flaw allows a user with Multisite subsite Administrator privileges to bypass the network-level restrictions typically reserved for a Network Super Admin.\nBy manipulating the setup-wizard installation request, an attacker can trigger the installation of arbitrary plugins hosted on the WordPress.org repository directly into the network-shared directory.\nThe risk implications are severe, as this grants subsite administrators the ability to install unauthorized code on a network-wide level, effectively escalating their privileges and potentially compromising the integrity of the entire WordPress Multisite installation.\nExploitation requires the attacker to hold at least subsite administrative access, making this a vertical privilege escalation vulnerability within the context of a WordPress Multisite environment.",
  "technicalDetails": "The vulnerability resides in the Envira Gallery plugin's setup-wizard initialization logic, specifically within the functions handling automated plugin installations. The root cause is a failure to validate the caller's permissions against the 'manage_network_plugins' or similar high-level WordPress capabilities required for network-wide administrative tasks.\nIn a standard WordPress Multisite configuration, only the Network Super Admin is authorized to install plugins that affect the entire network. However, the affected versions of Envira Gallery fail to restrict the setup-wizard installation request to this administrative role.\nWhen a subsite administrator triggers the setup-wizard, the plugin fails to verify if the requestor possesses the requisite network-level capabilities. Furthermore, the installation routine does not enforce a whitelist or curated list of allowed plugins, nor does it perform sufficient verification of the source package before executing the installation process.\nThe attack flow follows these steps: 1) The attacker authenticates as a subsite administrator; 2) The attacker crafts a request to the Envira Gallery setup-wizard installation endpoint; 3) The plugin processes the request without verifying the user's network-level privileges; 4) The plugin communicates with the WordPress.org plugin repository to fetch a plugin specified in the request; 5) The plugin installs the fetched code into the network-shared directory, bypassing the expected constraints.\nBecause the plugin facilitates the writing of files to the network-shared directory, this vulnerability allows for the unauthorized deployment of arbitrary code. This bypasses the typical barrier where subsite admins are restricted from installing plugins that could potentially affect the entire network environment.\nThe impact of this vulnerability is significant, as it enables an attacker to force the installation of vulnerable or malicious plugins, leading to potential Remote Code Execution (RCE), unauthorized data access, or total network takeover, depending on the nature of the plugin injected by the attacker."
}
CVE-2026-104680: Envira Gallery Improper Access Control (HIGH Severity, CVSS: 7.2) | Sceawere