Sceawere
Vulnerability Detail
CVE-2026-104681UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Envira Gallery Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Envira Gallery
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-11T07:17:22.660Z",
"pubdate": "2026-10-11T07:17:22.660Z",
"executiveSummary": "An authorization bypass and information disclosure vulnerability exists in the Envira Gallery WordPress plugin in versions prior to 1.16.2. The flaw is caused by missing object-level access controls when processing image identifiers added to galleries. By manipulating these identifiers, authenticated users with gallery creation and editing privileges—such as those assigned the Author role or higher by default—can circumvent standard WordPress access controls.\nExploitation of this vulnerability allows an attacker to improperly disclose the titles and excerpts of private, draft, pending, and trashed posts owned by other users, which WordPress core access policies would typically withhold from unauthorized accounts. This presents significant confidentiality risks to impacted WordPress deployments, enabling lower-privileged users to systematically harvest sensitive post metadata and unreleased content details.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure direct object reference (IDOR) and missing authorization checks within the media handling logic of the Envira Gallery plugin prior to version 1.16.2. When an authenticated user adds an image attachment to a gallery instance, the plugin processes an incoming request containing an image identifier representing the post ID of the asset. Rather than validating user access by invoking native WordPress capability functions or evaluating post status privacy parameters, the plugin directly queries the database for the supplied post object without restricting query results to authorized media items.\nIn WordPress architecture, media attachments, standard published posts, private posts, drafts, pending reviews, and trashed items are all stored within the central database table as distinct post types and statuses. Native WordPress core access controls prevent unauthorized accounts from viewing drafts, private content, or trashed items authored by other users. However, because the affected Envira Gallery plugin logic treats any provided post identifier as a valid media attachment without enforcing object-level authorization, an attacker can supply the unique integer ID of any database object.\nThe attack flow operates sequentially: First, an attacker authenticates to the target WordPress instance using an account equipped with gallery editing privileges (by default, the Author role or above). Second, the attacker creates a new gallery or opens an existing gallery for editing within the administrative interface. Third, the attacker crafts or intercepts a request to attach media, replacing legitimate attachment IDs with target post IDs corresponding to restricted content, such as private, draft, pending, or trashed posts belonging to other users.\nUpon receiving the manipulated request, the server-side plugin logic executes without verifying whether the caller possesses permission to view the requested object. The plugin extracts the target post's title and excerpt from the database and embeds this metadata into the gallery layout or administrative preview response. Consequently, the attacker gains unauthorized read access to sensitive post titles and excerpts that WordPress core would otherwise withhold, leading to widespread information disclosure across the target site."
}