Insecure Direct Object Reference in NextGEN Gallery by Imagely
CVE-2026-6566

4.3MEDIUM

What is CVE-2026-6566?

The NextGEN Gallery plugin for WordPress exhibits a vulnerability where insufficient authorization checks in the image deletion REST API allow authenticated users, even with minimal permissions, to delete images belonging to other users. The REST endpoint for deleting images only verifies 'NextGEN Manage gallery' permissions, neglecting to verify ownership of the gallery, which could lead to unauthorized access to and deletion of sensitive image assets.

Affected Version(s)

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery 0 <= 4.2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao Luu Gia Nguyen
.