Description


The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own.

Related CPE's


Could not find any relations

Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

2.7 · Low

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T06:16:38.747Z

26 hours ago

Last modified

2026-10-08T20:51:18.123Z

12 hours ago