Junglewise Threat Intelligence

CVE-2026-6566: Imagely NextGEN Gallery IDOR in image deletion REST flow

CVE-2026-6566 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Technologies: Imagely NextGEN Gallery. Vendors: Imagely.

Executive brief

NextGEN Gallery is a popular WordPress plugin used to manage and display photo galleries. A security flaw allows logged-in users with basic gallery management permissions to delete images belonging to other users. This could lead to the unauthorized removal of website content and permanent loss of image files from the server's storage.

Technical details

The NextGEN Gallery plugin for WordPress (up to version 4.2.0) contains an Insecure Direct Object Reference (IDOR) vulnerability in its REST API. The issue exists in the permission callback for the 'DELETE /imagely/v1/images/{id}' endpoint, which fails to verify gallery ownership or check for 'NextGEN Manage others gallery' permissions. An authenticated attacker with Subscriber-level privileges and the 'NextGEN Manage gallery' capability can exploit this to delete arbitrary image IDs. If the 'deleteImg' setting is enabled (the default configuration), the associated files are also deleted from the disk. A patch is available in the plugin's latest updates.

Affected products

  • Imagely NextGEN Gallery up to and including 4.2.0

Timeline

  • 2026-05-20: disclosed: Vulnerability published on NVD and Wordfence Intelligence.

References

Related threats