---
id: CVE-2026-81651
title: >-
  The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does
  not verify that the user saving a gallery owns it, allowing any user granted
  its gallery-management capability by an administrator to overwrite the stored
  sett…
summary: >-
  The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does
  not verify that the user saving a gallery owns it, allowing any user granted
  its gallery-management capability by an administrator to overwrite the stored
  sett…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
product: 'Photo Gallery, Sliders, Proofing and Themes'
affected:
  - photo_gallery_sliders_proofing_and_themes < 4.5.0
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81651'
references:
  - url: 'https://wpscan.com/vulnerability/69ccebff-414d-49bb-b914-cae87ab27f4f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.0995
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-20T13:47:46.786469Z'
ingestedAt: '2026-09-20T07:16:12.224Z'
---

## Overview

The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
