CVE-2026-81653: NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR
Published Sep 20, 2026
·Updated
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
Affected Software
1 affected component
NextGEN Gallery WordPress plugin<4.5.0
Event History
Sep 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user must be authenticated and have the plugin's gallery-management capability, which is granted by an administrator. Such a user can affect images in galleries owned by other users.
2
What actions can an affected user perform against another user's gallery images?
They can delete, copy, or re-tag any image on the site, including images belonging to galleries managed by other users.
3
Which installations are affected?
NextGEN Gallery WordPress plugin versions before 4.5.0 are affected.