PatchSiren cyber security CVE debrief
CVE-2026-104682 Envira Gallery CVE debrief
The Envira Gallery WordPress plugin before 1.16.2 has an authorization issue in its gallery-conversion feature. This allows users with contributor-level access to create and publish gallery posts that the plugin's settings would otherwise restrict them from creating. The issue arises from incorrect authorization checks, enabling potential unauthorized content creation and publication. Defenders should assess the impact and verify plugin versions to mitigate risks associated with this vulnerability.
- Vendor
- Envira Gallery
- Product
- Envira Gallery WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for WordPress installations with the Envira Gallery plugin should assess exposure and verify the version of the plugin. They should also review user access controls, particularly for contributor-level users, and ensure that appropriate restrictions are in place to prevent unauthorized gallery post creation and publication. Additionally, defenders should monitor for potential abuse and review compensating controls for exposed systems.
Why it matters
The Envira Gallery WordPress plugin before 1.16.2 has an authorization issue that allows contributor-level users to create and publish restricted gallery posts, potentially exposing sensitive information and impacting site integrity.
- Potential unauthorized creation and publication of gallery posts by contributor-level users.
- Possible exposure of sensitive information through gallery posts.
- Need for verification of plugin version and contributor-level access restrictions.
- Potential impact on site integrity and user trust.
Technical summary
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, allowing users with contributor-level access to create and publish gallery posts that the plugin's settings otherwise withhold from them. This issue stems from inadequate authorization checks, potentially leading to unauthorized content creation and publication. The vulnerability highlights the need for stricter access controls and version verification to prevent exploitation. Technical analysis indicates that the plugin fails to properly validate user permissions, enabling contributor-level users to bypass intended restrictions.
Defensive priority
Defenders should prioritize verifying the version of the Envira Gallery WordPress plugin and ensuring that contributor-level access is properly restricted.
Recommended defensive actions
- Verify the version of the Envira Gallery WordPress plugin and ensure it is up-to-date.
- Restrict contributor-level access to the plugin's gallery-conversion feature.
- Monitor for potential abuse of the plugin's gallery-conversion feature.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is needed to determine the affected versions and potential impact. The Envira Gallery WordPress plugin before 1.16.2's authorization issue allows contributor-level users to bypass restrictions on gallery post creation and publication. Evidence from the CVE record and NVD entry suggests a need for verification of plugin versions and contributor access restrictions. Additional review of plugin settings and user access controls is also
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104682 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104682
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104682 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104682
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/faaa0c75-64d7-4e92-99a6-e60805d2080b/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.