Junglewise Threat Intelligence

CVE-2026-54190: Envira Photo Gallery broken access control

CVE-2026-54190 · Severity: medium · CVSS 6.5 · Published 2026-06-16

Executive brief

Envira Photo Gallery is a popular WordPress plugin used to create and manage image galleries. A security flaw in versions 1.12.5 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to gallery settings or disruptions to how images are displayed on the website.

Technical details

A broken access control vulnerability exists in the Envira Photo Gallery plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions that should require higher privileges, potentially by bypassing nonce or permission checks. This can result in unauthorized modification of plugin data or settings (Integrity impact) and potential service disruption (Availability impact). The issue is resolved in version 1.12.6.

Affected products

  • Envira Gallery Envira Photo Gallery <= 1.12.5

Timeline

  • 2026-04-28: other: Vulnerability reported by researcher Tiago Ventura
  • 2026-06-15: advisory: Patchstack advisory published
  • 2026-06-16: disclosed: CVE published to NVD

References