Authorization Bypass in WP Chill Image Photo Gallery Plugin by WordPress
CVE-2026-39510

2.7LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39510?

An authorization bypass vulnerability exists in the WP Chill Image Photo Gallery Final Tiles Grid, affecting versions up to 3.6.11. This vulnerability allows attackers to exploit incorrectly configured access control security levels, leading to unauthorized access to sensitive data. By manipulating user-controlled keys, unauthorized users may gain access to resources that should be restricted, posing significant security risks for websites utilizing this plugin.

Affected Version(s)

Image Photo Gallery Final Tiles Grid 0 <= 3.6.11

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jitlada | Patchstack Bug Bounty Program
.