Junglewise Threat Intelligence

CVE-2026-39510: WP Chill Image Photo Gallery Final Tiles Grid IDOR in access control

CVE-2026-39510 · Severity: low · CVSS 2.7 · Published 2026-04-08

Vendors: WP Chill.

Executive brief

The Image Photo Gallery Final Tiles Grid plugin for WordPress, which is used to create tiled image galleries and portfolios, contains a security flaw in its access control settings. An attacker with high-level site permissions (such as an Author) could potentially access or interact with data they should not be able to see by manipulating internal identifiers. While the risk to customer data is low, it represents a failure in the plugin's ability to strictly enforce user permissions.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the WP Chill Image Photo Gallery Final Tiles Grid plugin (final-tiles-grid-gallery-lite) through version 3.6.11. The flaw stems from an authorization bypass through a user-controlled key, allowing users to exploit incorrectly configured access control security levels. An attacker with 'Author' or higher privileges can manipulate input keys to interact with objects or data outside of their intended scope. The vulnerability is addressed in version 3.6.12.

Affected products

  • WP Chill Image Photo Gallery Final Tiles Grid (final-tiles-grid-gallery-lite) <= 3.6.11

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher
  • 2026-02-11: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published
  • 2026-03-12: patched: Patch released in version 3.6.12

References