Missing Authorization in WP Chill Image Photo Gallery Final Tiles Grid by WordPress
CVE-2026-27424

4.3MEDIUM

What is CVE-2026-27424?

A missing authorization vulnerability exists in the WP Chill Image Photo Gallery Final Tiles Grid, which can lead to exploitation through improperly configured access control security levels. This flaw allows unauthorized users to gain access to restricted features and data, posing a significant risk to website integrity. The affected versions range from n/a to 3.6.11, highlighting the importance of updating to mitigate potential security breaches.

Affected Version(s)

Image Photo Gallery Final Tiles Grid <= 3.6.11

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Que Thanh Tuan | Patchstack Bug Bounty Program
.