---
id: CVE-2026-81654
title: >-
  The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does
  not check that a user holds its options capability before saving image sizing
  settings, allowing users granted only its gallery-management capability by an
  adm…
summary: >-
  The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does
  not check that a user holds its options capability before saving image sizing
  settings, allowing users granted only its gallery-management capability by an
  adm…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
product: 'Photo Gallery, Sliders, Proofing and Themes'
affected:
  - photo_gallery_sliders_proofing_and_themes < 4.5.0
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81654'
references:
  - url: 'https://wpscan.com/vulnerability/bede7803-8ffd-4e17-852e-bce634466fcb/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.09949
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-20T13:48:32.587317Z'
ingestedAt: '2026-09-20T07:16:12.223Z'
---

## Overview

The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
