# Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Insecure Direct Object Reference to Gallery Image Modification and Disclosure

- **ID:** WPSEC-2026-0626
- **Plugin:** Portfolio Filter Gallery – Photo Gallery (`portfolio-filter-gallery`), https://wordpress.org/plugins/portfolio-filter-gallery/
- **Affected versions:** from 2.0.0 before 2.2.1
- **Fixed in:** 2.2.1 (Update to 2.2.1 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/portfolio-filter-gallery
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0626/

## Description

The Portfolio Gallery – Image Gallery Plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 up to, and including, 2.2.0 due to missing per-object authorization checks on the user-supplied 'gallery_id' parameter in several gallery AJAX actions. These actions only checked a generic capability, never whether the user could edit the specific gallery. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, remove, reorder or modify images in galleries owned by other users, to read the image data of arbitrary galleries including private and draft ones, and to duplicate other users' galleries.

## References

- https://wpsec.com/vuln/WPSEC-2026-0626/
- https://plugins.svn.wordpress.org/portfolio-filter-gallery/tags/2.2.1/
- https://wordpress.org/plugins/portfolio-filter-gallery/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0626/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
