CVE-2026-105976 PUBLISHED

Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Actions

Assigner: WPScan
Reserved: 06.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.

Product Status

Vendor Unknown
Product Portfolio Filter Gallery
Versions Default: unaffected
  • affected from 0 to 2.2.1 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE