Insecure Direct Object Reference in NextGEN Gallery by Imagely
CVE-2026-6566
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 May 2026
What is CVE-2026-6566?
The NextGEN Gallery plugin for WordPress exhibits a vulnerability where insufficient authorization checks in the image deletion REST API allow authenticated users, even with minimal permissions, to delete images belonging to other users. The REST endpoint for deleting images only verifies 'NextGEN Manage gallery' permissions, neglecting to verify ownership of the gallery, which could lead to unauthorized access to and deletion of sensitive image assets.
Affected Version(s)
Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery 0 <= 4.2.0