The Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized changes to data. This means that anyone with access to the plugin, at a contributor level or higher, can make changes to other user’s galleries. This affects all versions of the plugin up to and including version 1.8.7.1.