Executive brief
The Image Photo Gallery Final Tiles Grid plugin for WordPress, which is used to create and manage image galleries, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions (such as subscribers) to perform actions or access data they should not be authorized to see. While the impact is considered low, it could lead to unauthorized changes or information disclosure within the gallery management system.
Technical details
A missing authorization vulnerability (CWE-862) exists in the WP Chill Image Photo Gallery Final Tiles Grid plugin for WordPress through version 3.6.11. The flaw is rooted in incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker authenticated with basic 'Subscriber' level privileges can exploit this over the network to perform unauthorized actions or access restricted data. The vulnerability is addressed in version 3.6.12.
Affected products
- WP Chill Image Photo Gallery Final Tiles Grid <= 3.6.11
Timeline
- 2025-10-23: other: Reported by Que Thanh Tuan
- 2026-05-20: advisory: Published by Patchstack and NVD
- 2026-05-20: patched: Patch released in version 3.6.12