PatchSiren

farazfrank CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH farazfrank CVE published 2026-09-18

CVE-2026-89413

The Filter Gallery plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.1.4. This allows authenticated attackers with subscriber-level access and above to delete arbitrary Filter Gallery records, including associated filters, image mappings, settings, and details options, by supplying attacker-controlled gallery IDs.

MEDIUM farazfrank CVE published 2026-09-18

CVE-2026-89138

The Filter Gallery plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.1.4. This allows authenticated attackers with subscriber-level access and above to overwrite titles and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.