CVE-2026-39510 LOW

CVE-2026-39510: WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Insecure Direct Object References (IDOR) vulnerability

Vendor Wp Chill
Product Image Photo Gallery Final Tiles Grid
Weakness CWE-639 · IDOR
Published April 8, 2026
Last update April 29, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.

Explanation of Vulnerability in Simple Terms

02Summary

Image Photo Gallery Final Tiles Grid versions up to 3.6.11 contain an authorization flaw that allows high-privilege users to access sensitive information they should not see. The vulnerability requires administrator-level access and does not affect data integrity or availability. A patch status is not yet confirmed.

What an attacker can do

03Attacker Capabilities

Read sensitive information on the site if they have administrator access.

Potential impact on your site

04Site Impact

Site administrators with malicious intent or compromised admin accounts can view confidential data.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level privileges on the WordPress site.

Key dates

06Disclosure timeline

April 8, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE