PT-2026-3517 · WordPress · Image Photo Gallery Final Tiles Grid

Pouria Shahba

·

Publicado

2026-01-19

·

Atualizado

2026-01-20

·

CVE-2025-15466

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Image Photo Gallery Final Tiles Grid plugin for WordPress versions through 3.6.9
Description The software is susceptible to unauthorized access and modification of data because of absent capability checks on several AJAX actions. Authenticated attackers possessing Contributor-level access or higher can view, create, modify, clone, delete, and reassign ownership of galleries, even those created by administrators. The affected AJAX actions do not properly verify user permissions before allowing operations on gallery data.
Recommendations Update the Image Photo Gallery Final Tiles Grid plugin to a version beyond 3.6.9.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15466

Produtos afetados

Image Photo Gallery Final Tiles Grid