CVE-2023-2561: Gallery-Metabox Project Gallery-Metabox

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.

Affected products

Published 2023-07-12. Last modified 2026-06-17.