Sceawere

Vulnerability Detail

CVE-2026-104684UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Envira Gallery Unauthorized Metadata Exposure

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
8h ago
Vendor
Unknown
Product
Envira Gallery
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-11T07:17:22.867Z",
  "pubdate": "2026-10-11T07:17:22.867Z",
  "executiveSummary": "The Envira Gallery WordPress plugin prior to version 1.16.2 contains an authorization bypass vulnerability that enables the unauthorized disclosure of gallery metadata. This flaw stems from improper access control validation when processing requests to render gallery content.\nThe vulnerability allows an unauthenticated attacker to view metadata associated with galleries that are intended to be non-public. Because the system fails to verify the user's authorization level before rendering the gallery output, internal or private information indexed by the plugin becomes exposed to external parties.\nThe impact includes the unauthorized leakage of potentially sensitive metadata, which may include gallery configurations, file paths, or titles. This risk primarily affects WordPress installations utilizing the Envira Gallery plugin where gallery visibility settings are intended to restrict content based on user roles. No specific administrative or high-level privileges are required to trigger this exposure, as the lack of authentication check allows any visitor to query the metadata via crafted requests.\nOrganizations using affected versions of Envira Gallery should prioritize upgrading to version 1.16.2 or later to enforce proper access control mechanisms and prevent the inadvertent exposure of private gallery metadata.",
  "technicalDetails": "The vulnerability is classified as an authorization bypass, specifically an improper check for authorization within the plugin's rendering logic. The root cause lies in the application's failure to perform adequate access control checks (ACCs) or verify the caller's session permissions before executing functions that retrieve and render gallery metadata.\nIn the affected versions, the plugin code responsible for displaying or processing gallery shortcodes or blocks does not implement a secondary validation layer to confirm if the current request context is permitted to view the requested gallery object. Consequently, when a gallery object is called, the application logic proceeds to process the data retrieval regardless of the current user's authentication status or authorization level.\nThe attack flow involves an attacker identifying the endpoint or the mechanism that renders the Envira Gallery output. By supplying the identifier for a non-public or private gallery, the attacker forces the plugin to fetch the corresponding metadata from the database. Because the rendering function lacks a privilege check, it fetches the metadata object and renders it as part of the public-facing response. An attacker does not require elevated privileges; they can interact with the plugin's frontend exposure points to leak information that should be restricted to authenticated authors or administrators.\nThis vulnerability is particularly impactful because it bypasses the intended privacy model of the WordPress site. While the gallery content might be intended for draft status or limited to specific user roles, the plugin's flawed rendering logic effectively ignores these constraints. The exposure of metadata can provide attackers with structural information about the site's media assets, which could serve as a reconnaissance step for further exploitation. The lack of validation ensures that the exposure is persistent for any gallery ID that can be guessed or discovered through directory enumeration or other passive reconnaissance techniques.\nThe scope of this vulnerability covers all versions of Envira Gallery prior to 1.16.2. The flaw is not limited to specific server configurations and resides entirely within the application code of the plugin. Remediation requires an update to 1.16.2, which introduces the necessary security checks to validate the current user's session and permissions before proceeding with the gallery metadata rendering process."
}
CVE-2026-104684: Envira Gallery Unauthorized Metadata Exposure (LOW Severity, CVSS: 2.7) | Sceawere