CVE-2026-39510: WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39510?
CVE-2026-39510 is categorized as a medium severity vulnerability due to its impact on authorization bypass and exposing sensitive information.
How do I fix CVE-2026-39510?
To fix CVE-2026-39510, upgrade the WP Chill Image Photo Gallery Final Tiles Grid plugin to version 3.6.12 or later.
What does CVE-2026-39510 target?
CVE-2026-39510 targets the WP Chill Image Photo Gallery Final Tiles Grid plugin, specifically versions less than or equal to 3.6.11.
What type of vulnerability is CVE-2026-39510?
CVE-2026-39510 is classified as an Insecure Direct Object References (IDOR) vulnerability.
What can attackers do with CVE-2026-39510?
Attackers can exploit CVE-2026-39510 to bypass authorization controls and gain access to unauthorized resources.