WordPress · Photo Gallery · CVE-2026-81651
**Name of the Vulnerable Software and Affected Versions**
The Photo Gallery, Sliders, Proofing and WordPress plugin versions prior to 4.5.0
**Description**
The plugin fails to verify if the user saving a gallery is the actual owner. This allows any user with the gallery-management capability to overwrite stored settings for any gallery on the site, including the filesystem path and galleries belonging to other users.
**Recommendations**
Update the plugin to version 4.5.0 or later.