CVE-2026-81651: CWE-639 Authorization Bypass Through User-Controlled Key in Photo Gallery, Sliders, Proofing and Themes
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.
AI Analysis
Technical Summary
The Photo Gallery, Sliders, Proofing and Themes WordPress plugin versions prior to 4.5.0 contain an authorization bypass vulnerability (CWE-639). The plugin fails to verify ownership when a user attempts to save a gallery, permitting any user granted the gallery-management capability by an administrator to overwrite stored settings of any gallery on the site. This flaw allows modification of galleries belonging to other users, including critical settings such as the filesystem path.
Potential Impact
An attacker with gallery-management capability can overwrite the stored settings of any gallery on the site, including those owned by other users. This could lead to unauthorized modification of gallery content and potentially affect the filesystem path configuration, which may have further security implications depending on the site's setup.
Mitigation Recommendations
Upgrade the Photo Gallery, Sliders, Proofing and Themes plugin to version 4.5.0 or later where this vulnerability is fixed. No other mitigation guidance is provided, and patch status is confirmed by the version boundary.
CVE-2026-81651: CWE-639 Authorization Bypass Through User-Controlled Key in Photo Gallery, Sliders, Proofing and Themes
Description
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.
CVSS v3.1
Score 3.1low
Affected software
Photo Gallery, Sliders, Proofing and Themes
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Photo Gallery, Sliders, Proofing and Themes WordPress plugin versions prior to 4.5.0 contain an authorization bypass vulnerability (CWE-639). The plugin fails to verify ownership when a user attempts to save a gallery, permitting any user granted the gallery-management capability by an administrator to overwrite stored settings of any gallery on the site. This flaw allows modification of galleries belonging to other users, including critical settings such as the filesystem path.
Potential Impact
An attacker with gallery-management capability can overwrite the stored settings of any gallery on the site, including those owned by other users. This could lead to unauthorized modification of gallery content and potentially affect the filesystem path configuration, which may have further security implications depending on the site's setup.
Mitigation Recommendations
Upgrade the Photo Gallery, Sliders, Proofing and Themes plugin to version 4.5.0 or later where this vulnerability is fixed. No other mitigation guidance is provided, and patch status is confirmed by the version boundary.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-27T09:27:32.697Z
- State
- PUBLISHED
Threat ID: 6aaf7de855bf5e2cf5adcf94
Added to database: 09/20/2026, 06:32:08 UTC
Last enriched: 09/20/2026, 06:47:38 UTC
Last updated: 09/20/2026, 22:12:34 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.