Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Missing Authorization to Site-Wide Filter Management

Medium 4.3 CWE-862Fixed in 2.2.1
ID
WPSEC-2026-0630
Plugin
Portfolio Filter Gallery – Photo Gallery (portfolio-filter-gallery)
Affected
from 2.0.0 before 2.2.1
Remediation
Update to 2.2.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Portfolio Gallery – Image Gallery Plugin on WPSec AttackSurface
Fix released
Published

Description

The Portfolio Filter Gallery plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.2.0 due to the filter management AJAX handlers and Filters admin page only requiring generic gallery management capabilities (edit_posts level) rather than administrator privileges. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, update, and delete the site-wide gallery filters used across all galleries.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0