Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Insecure Direct Object Reference to Gallery Image Modification and Disclosure
- ID
- WPSEC-2026-0626
- Plugin
- Portfolio Filter Gallery – Photo Gallery (portfolio-filter-gallery)
- Affected
- from 2.0.0 before 2.2.1
- Remediation
- Update to 2.2.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Portfolio Gallery – Image Gallery Plugin on WPSec AttackSurface
- Fix released
- Published
Description
The Portfolio Gallery – Image Gallery Plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 up to, and including, 2.2.0 due to missing per-object authorization checks on the user-supplied 'gallery_id' parameter in several gallery AJAX actions. These actions only checked a generic capability, never whether the user could edit the specific gallery. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, remove, reorder or modify images in galleries owned by other users, to read the image data of arbitrary galleries including private and draft ones, and to duplicate other users' galleries.
References
- https://wpsec.com/vuln/WPSEC-2026-0626/
- https://plugins.svn.wordpress.org/portfolio-filter-gallery/tags/2.2.1/
- https://wordpress.org/plugins/portfolio-filter-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS