Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Insecure Direct Object Reference to Gallery Image Modification and Disclosure

Medium 5.4 CWE-639Fixed in 2.2.1
ID
WPSEC-2026-0626
Plugin
Portfolio Filter Gallery – Photo Gallery (portfolio-filter-gallery)
Affected
from 2.0.0 before 2.2.1
Remediation
Update to 2.2.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Portfolio Gallery – Image Gallery Plugin on WPSec AttackSurface
Fix released
Published

Description

The Portfolio Gallery – Image Gallery Plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 up to, and including, 2.2.0 due to missing per-object authorization checks on the user-supplied 'gallery_id' parameter in several gallery AJAX actions. These actions only checked a generic capability, never whether the user could edit the specific gallery. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, remove, reorder or modify images in galleries owned by other users, to read the image data of arbitrary galleries including private and draft ones, and to duplicate other users' galleries.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0