CVE-2026-104079
Description détaillée
Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that allows lower-privileged authenticated users to create and publish Envira galleries without the required capabilities, because the endpoint only checks edit permissions on the source post and uses a hard-coded publish status. Attackers can also supply arbitrary caller-controlled image IDs without ownership verification to publish unauthorized content using attachments they are not authorized to use.
Vecteur d'attaque (CVSS)
Dernières Vulnérabilités
CVE-2026-94067
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.
CVE-2026-94066
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpabRice Pond pond allows Reflected XSS.This issue affects Pond: from n/a through 2.6.1.
CVE-2026-94065
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
