Data Modification Vulnerability in Meow Gallery Plugin for WordPress
CVE-2026-1291
4.3MEDIUM
What is CVE-2026-1291?
The Meow Gallery plugin for WordPress has a serious vulnerability that allows authenticated users with Author-level access and higher to modify gallery shortcode records. This is due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode. Attackers can exploit this flaw by supplying a user-controlled id value, enabling them to perform database updates without proper authorization checks, potentially leading to unauthorized creation or overwriting of gallery records.
Affected Version(s)
Meow Gallery 0 <= 5.4.4