The WP Easy Gallery plugin for WordPress has a security issue that allows unauthorized access. This is because certain functions, like wpeg_settings and wpeg_add_gallery, do not have a capability check when used with AJAX. This vulnerability affects all versions of the plugin, up to and including 4.8.5. As a result, attackers with subscriber-level access or higher can make changes to galleries without proper authorization.