Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
WP Chill Image Photo Gallery: Unauthorized Access to Images
CVE-2026-39510
Summary
A security weakness in the WP Chill Image Photo Gallery allows hackers to view images they shouldn't be able to see if the access controls are not set up correctly. If you use this plugin, make sure to update to the latest version to prevent unauthorized access to your images. This issue affects versions up to 3.6.11, so update as soon as possible.
Original title
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control...
Original description
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
Published: 8 Apr 2026 · Updated: 9 Apr 2026 · First seen: 8 Apr 2026