Executive brief
Meow Gallery is a WordPress plugin used to create and manage image galleries. A security flaw allows users with 'Author' level access or higher to modify or overwrite gallery settings and records that they do not own. This could lead to unauthorized changes to website content or the disruption of existing image galleries.
Technical details
The Meow Gallery plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) / Missing Authorization vulnerability in versions up to 5.4.4. The vulnerability exists within the REST API endpoint `/wp-json/meow-gallery/v1/save_shortcode` due to a missing capability check. Authenticated attackers with Author-level permissions or higher can exploit this by providing a user-controlled 'id' value to create or overwrite existing gallery shortcode records. The endpoint performs database update operations without verifying if the requesting user has the authority to modify the specific record. This issue was addressed in version 5.4.5 by updating permission checks to use the 'can_access_settings' capability.
Affected products
- Jordy Meow Meow Gallery up to, and including, 5.4.4
Timeline
- 2026-02-25: patched: Fixed in version 5.4.5
- 2026-06-13: disclosed: CVE published
References
- https://plugins.trac.wordpress.org/browser/meow-gallery/trunk/classes/rest.php
- https://plugins.trac.wordpress.org/changeset/3469543/meow-gallery
- https://plugins.trac.wordpress.org/changeset/3469543/meow-gallery/trunk/classes/rest.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fmeow-gallery/tags/5.4.4&new_path=%2Fmeow-gallery/tags/5.4.5
- https://wordpress.org/plugins/meow-gallery/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3386ea07-9c61-4b54-a451-1178ca6325cb?source=cve