Sceawere
Vulnerability Detail
CVE-2026-104680UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Envira Gallery Improper Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Envira Gallery
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-11T07:17:22.550Z",
"pubdate": "2026-10-11T07:17:22.550Z",
"executiveSummary": "The Envira Gallery WordPress plugin prior to version 1.16.2 contains a critical authorization vulnerability related to the handling of setup-wizard installation requests.\nThe vulnerability is categorized as an Improper Access Control issue, where the plugin fails to perform adequate capability checks before processing installation routines.\nThis flaw allows a user with Multisite subsite Administrator privileges to bypass the network-level restrictions typically reserved for a Network Super Admin.\nBy manipulating the setup-wizard installation request, an attacker can trigger the installation of arbitrary plugins hosted on the WordPress.org repository directly into the network-shared directory.\nThe risk implications are severe, as this grants subsite administrators the ability to install unauthorized code on a network-wide level, effectively escalating their privileges and potentially compromising the integrity of the entire WordPress Multisite installation.\nExploitation requires the attacker to hold at least subsite administrative access, making this a vertical privilege escalation vulnerability within the context of a WordPress Multisite environment.",
"technicalDetails": "The vulnerability resides in the Envira Gallery plugin's setup-wizard initialization logic, specifically within the functions handling automated plugin installations. The root cause is a failure to validate the caller's permissions against the 'manage_network_plugins' or similar high-level WordPress capabilities required for network-wide administrative tasks.\nIn a standard WordPress Multisite configuration, only the Network Super Admin is authorized to install plugins that affect the entire network. However, the affected versions of Envira Gallery fail to restrict the setup-wizard installation request to this administrative role.\nWhen a subsite administrator triggers the setup-wizard, the plugin fails to verify if the requestor possesses the requisite network-level capabilities. Furthermore, the installation routine does not enforce a whitelist or curated list of allowed plugins, nor does it perform sufficient verification of the source package before executing the installation process.\nThe attack flow follows these steps: 1) The attacker authenticates as a subsite administrator; 2) The attacker crafts a request to the Envira Gallery setup-wizard installation endpoint; 3) The plugin processes the request without verifying the user's network-level privileges; 4) The plugin communicates with the WordPress.org plugin repository to fetch a plugin specified in the request; 5) The plugin installs the fetched code into the network-shared directory, bypassing the expected constraints.\nBecause the plugin facilitates the writing of files to the network-shared directory, this vulnerability allows for the unauthorized deployment of arbitrary code. This bypasses the typical barrier where subsite admins are restricted from installing plugins that could potentially affect the entire network environment.\nThe impact of this vulnerability is significant, as it enables an attacker to force the installation of vulnerable or malicious plugins, leading to potential Remote Code Execution (RCE), unauthorized data access, or total network takeover, depending on the nature of the plugin injected by the attacker."
}