CVE-2026-105977 PUBLISHED

Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion via pfg_delete_video_thumbnail

Assigner: WPScan
Reserved: 06.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.

Product Status

Vendor Unknown
Product Portfolio Filter Gallery
Versions Default: unaffected
  • affected from 2.0.2 to 2.2.1 (excl.)

Credits

  • blast finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE