Ghostwire

CVE-2026-104682: The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion...

MEDIUM CVSS 0.0

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References