Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-104681
CVE-2026-104681
Description
The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.16.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.