Ghostwire

CVE-2026-104681: The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to...

MEDIUM CVSS 0.0

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References