PT-2026-95929 · WordPress · Meow Gallery
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Meow Gallery versions prior to 5.5.5
Description
Insufficient capability checks in the
fetch posts function allow authenticated users with Author-level access or higher to access post data that should be restricted. This flaw enables the disclosure of titles, authors, dates, and statuses of draft and private posts belonging to other users.Recommendations
Update Meow Gallery to version 5.5.5 or later.
As a temporary mitigation, restrict user roles to prevent unauthorized accounts from having Author-level access or higher.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meow Gallery