Vulnerabilities / Portfolio Gallery – Image Gallery Plugin / WPSEC-2026-0630
Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Missing Authorization to Site-Wide Filter Management
Medium 4.3
CWE-862Fixed in 2.2.1
- ID
- WPSEC-2026-0630
- Plugin
- Portfolio Filter Gallery – Photo Gallery (portfolio-filter-gallery)
- Affected
- from 2.0.0 before 2.2.1
- Remediation
- Update to 2.2.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Portfolio Gallery – Image Gallery Plugin on WPSec AttackSurface
- Fix released
- Published
Description
The Portfolio Filter Gallery plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.2.0 due to the filter management AJAX handlers and Filters admin page only requiring generic gallery management capabilities (edit_posts level) rather than administrator privileges. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, update, and delete the site-wide gallery filters used across all galleries.
References
- https://wpsec.com/vuln/WPSEC-2026-0630/
- https://plugins.svn.wordpress.org/portfolio-filter-gallery/tags/2.2.1/
- https://wordpress.org/plugins/portfolio-filter-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS