{"id":"CVE-2026-81651","published":"2026-09-20T07:16:49.700","lastModified":"2026-09-21T13:34:57.127","description":"The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.","cvssScore":3.1,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/69ccebff-414d-49bb-b914-cae87ab27f4f/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}