Executive brief
The Image Photo Gallery Final Tiles Grid plugin for WordPress, which is used to create tiled image galleries and portfolios, contains a security flaw in its access control settings. An attacker with high-level site permissions (such as an Author) could potentially access or interact with data they should not be able to see by manipulating internal identifiers. While the risk to customer data is low, it represents a failure in the plugin's ability to strictly enforce user permissions.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the WP Chill Image Photo Gallery Final Tiles Grid plugin (final-tiles-grid-gallery-lite) through version 3.6.11. The flaw stems from an authorization bypass through a user-controlled key, allowing users to exploit incorrectly configured access control security levels. An attacker with 'Author' or higher privileges can manipulate input keys to interact with objects or data outside of their intended scope. The vulnerability is addressed in version 3.6.12.
Affected products
- WP Chill Image Photo Gallery Final Tiles Grid (final-tiles-grid-gallery-lite) <= 3.6.11
Timeline
- 2026-01-12: other: Vulnerability reported by researcher
- 2026-02-11: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published
- 2026-03-12: patched: Patch released in version 3.6.12