The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does not enforce gallery ownership or 'NextGEN Manage others gallery' permissions. This makes it possible for authenticated attackers, with Subscriber-level privileges and 'NextGEN Manage gallery' capability, to delete gallery images belonging to other users as well as their associated image files from disk when deleteImg is enabled (default).
History

Wed, 20 May 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Smub
Smub photo Gallery, Sliders, Proofing And Themes – Nextgen Gallery
Wordpress
Wordpress wordpress
Vendors & Products Smub
Smub photo Gallery, Sliders, Proofing And Themes – Nextgen Gallery
Wordpress
Wordpress wordpress

Wed, 20 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does not enforce gallery ownership or 'NextGEN Manage others gallery' permissions. This makes it possible for authenticated attackers, with Subscriber-level privileges and 'NextGEN Manage gallery' capability, to delete gallery images belonging to other users as well as their associated image files from disk when deleteImg is enabled (default).
Title Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-20T05:31:10.536Z

Reserved: 2026-04-18T17:51:56.808Z

Link: CVE-2026-6566

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-20T07:16:16.030

Modified: 2026-05-20T07:16:16.030

Link: CVE-2026-6566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T07:30:25Z