What the vulnerability does
01Description
Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5.
Explanation of Vulnerability in Simple Terms
02Summary
The Image Gallery plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to access sensitive gallery data they should not be able to view. An attacker with a basic user account can read information about galleries and their contents without proper permission checks. This affects versions up to 1.4.5.
What an attacker can do
03Attacker Capabilities
Read gallery data and metadata that should be restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Private or restricted gallery content may be exposed to low-privilege users who should not access it.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
June 10, 2024
CVE published
April 28, 2026
Record updated