CVE-2026-27424: WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Image Photo Gallery Final Tiles Gridto a version that resolves this vulnerability.Fixed in 3.6.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27424?
CVE-2026-27424 is classified as a critical vulnerability due to its impact on access control security levels.
How do I fix CVE-2026-27424?
To fix CVE-2026-27424, you should update the WP Chill Image Photo Gallery Final Tiles Grid plugin to version 3.6.12 or later.
What types of attacks can exploit CVE-2026-27424?
CVE-2026-27424 can be exploited by attackers to gain unauthorized access to sensitive content or information within the WordPress site.
Who is affected by CVE-2026-27424?
Users of WP Chill Image Photo Gallery Final Tiles Grid plugin version 3.6.11 and below are affected by CVE-2026-27424.
What specific vulnerability type is CVE-2026-27424?
CVE-2026-27424 is a Broken Access Control vulnerability that involves missing authorization checks.