CVE-2026-90978 PUBLISHED

Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check

Assigner: WPScan
Reserved: 14.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.

Product Status

Vendor Unknown
Product Filter Gallery
Versions Default: unaffected
  • affected from 1.1.2 to 1.1.5 (excl.)

Credits

  • Seongwon Lee finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE