Sceawere
Vulnerability Detail
CVE-2026-104682UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Envira Gallery Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Envira Gallery
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-11T07:17:22.763Z",
"pubdate": "2026-10-11T07:17:22.763Z",
"executiveSummary": "The Envira Gallery WordPress plugin prior to version 1.16.2 contains an improper authorization vulnerability within its gallery-conversion feature.\nThis security flaw allows authenticated users with contributor-level access to bypass intended restrictions regarding gallery creation and publishing.\nBy failing to properly validate authorization scopes, the plugin grants lower-privileged users the ability to perform actions reserved for higher-privileged accounts.\nThe vulnerability represents a significant risk to content integrity and access control within the WordPress environment, as attackers can escalate their capabilities to create content that should be prohibited by plugin-level permissions.\nExploitation requires the attacker to have at least a contributor-level account on the WordPress site. No specialized remote network exposure is necessary beyond standard authenticated access to the target WordPress installation.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient authorization check within the gallery-conversion mechanism of the Envira Gallery WordPress plugin. Specifically, the plugin incorrectly validates the requester's permissions by checking if the user has the ability to edit an arbitrary post rather than verifying the requisite capability to create or publish content managed specifically by the Envira Gallery framework.\nIn the context of the WordPress permission model, the 'edit_post' capability often suffices for modifying specific post types, but it does not equate to the administrative rights required for managing plugin-specific galleries. Because the code performs a surrogate check against an arbitrary post ID rather than enforcing global plugin permissions, an authenticated user—such as a contributor—can leverage this bypass to perform unauthorized actions.\nThe attack flow proceeds as follows: An authenticated user with contributor-level access invokes the gallery-conversion endpoint. The application processes the request by identifying the provided post reference. The plugin's security logic checks the user's current session against the ability to edit that post; since contributors generally possess edit rights for their own content, this validation logic returns a successful 'true' result. Consequently, the plugin proceeds to execute the gallery-conversion logic, effectively ignoring the global restrictions intended to prevent contributors from creating or modifying Envira Gallery objects.\nThis flaw effectively permits a contributor to circumvent the principle of least privilege, allowing for the unauthorized creation and publishing of galleries. Since the plugin's internal settings are designed to withhold such administrative capabilities from this role, the bypass results in a direct violation of the configured security policy. Once a gallery is created or converted via this method, it may be published or utilized in ways that the site administrator intended to restrict. There is no evidence that this requires complex exploit payloads; rather, it is a logic flaw in how the plugin handles request authorization, making the exploitation trivial for any authenticated user with access to the gallery-conversion feature."
}