What the vulnerability does
01Description
Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Video Gallery plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to access sensitive gallery data they should not be able to view. An attacker with a basic user account can read information from galleries without proper permission checks. This affects versions up to 1.5.3. Update to a version newer than 1.5.3 to resolve the issue.
What an attacker can do
03Attacker Capabilities
Read gallery data and metadata they do not have permission to access.
Potential impact on your site
04Site Impact
Unauthorized users can view private or restricted gallery content, potentially exposing sensitive images or metadata.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
May 6, 2024
CVE published
April 28, 2026
Record updated