
My new CVE-2026-104079: Envira Gallery Lite, 100k+ installs. REST endpoint checks you can edit the post, never that you can publish a gallery, then hardcodes status=publish. Contributor+ can publish galleries using media they don’t own. Fixed in 1.16.2. https://lazytitan.ro/envira
