PT-2026-99531 · WordPress · Event Gallery

CVE-2026-100747

·

Published

2026-09-27

·

Updated

2026-09-30

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Event Gallery versions prior to 6.5.0
Description Cross-Site Request Forgery (CSRF) occurs during the image upload process due to the absence of a CSRF token check. This allows a third-party site to upload files to an event and overwrite existing files that share the same name.
Recommendations Update to version 6.5.0 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100747

Affected Products

Event Gallery