Executive brief
NextGEN Gallery is a WordPress plugin that manages photo galleries on websites. A flaw in the plugin allows users with gallery-management permissions to delete, copy, and re-tag images in galleries they don't own, potentially resulting in loss of content or unauthorized modification of other users' image metadata.
Technical details
The plugin fails to verify ownership of galleries when processing image operations, creating an insecure direct object reference (IDOR). An authenticated user with gallery-management capability granted by an administrator can manipulate image identifiers to access and modify images in any gallery on the site. The vulnerability requires authentication and administrator-granted privileges but no user interaction from victims.
Affected products
- Photogallery NextGEN Gallery before 4.5.0
Timeline
- 2026-09-18: disclosed
- 2026-09-20: patched: Fixed in version 4.5.0