# Portfolio Gallery – Image Gallery Plugin <= 2.2.0 - Authenticated (Contributor+) Missing Authorization to Site-Wide Filter Management

- **ID:** WPSEC-2026-0630
- **Plugin:** Portfolio Filter Gallery – Photo Gallery (`portfolio-filter-gallery`), https://wordpress.org/plugins/portfolio-filter-gallery/
- **Affected versions:** from 2.0.0 before 2.2.1
- **Fixed in:** 2.2.1 (Update to 2.2.1 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/portfolio-filter-gallery
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0630/

## Description

The Portfolio Filter Gallery plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.2.0 due to the filter management AJAX handlers and Filters admin page only requiring generic gallery management capabilities (edit_posts level) rather than administrator privileges. This makes it possible for authenticated attackers, with Contributor-level access and above, to add, update, and delete the site-wide gallery filters used across all galleries.

## References

- https://wpsec.com/vuln/WPSEC-2026-0630/
- https://plugins.svn.wordpress.org/portfolio-filter-gallery/tags/2.2.1/
- https://wordpress.org/plugins/portfolio-filter-gallery/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0630/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
