PatchSiren

Envira Gallery CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Envira Gallery CVE published 2026-10-11

CVE-2026-104684

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors. This vulnerability can lead to unauthorized access to sensitive information and potential exposure of non-public gallery metadata. Defenders should assess the exposure an [truncated]

Review Envira Gallery CVE published 2026-10-11

CVE-2026-104682

The Envira Gallery WordPress plugin before 1.16.2 has an authorization issue in its gallery-conversion feature. This allows users with contributor-level access to create and publish gallery posts that the plugin's settings would otherwise restrict them from creating. The issue arises from incorrect authorization checks, enabling potential unauthorized content creation and publication. Defenders should ass [truncated]

Review Envira Gallery CVE published 2026-10-11

CVE-2026-104681

The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view. This allows any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.

Review Envira Gallery CVE published 2026-10-11

CVE-2026-104680

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing plugins before processing its setup-wizard installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published plugin into the network-shared directory, a privilege M [truncated]