The Filter Gallery plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.1.4. This allows authenticated attackers with subscriber-level access and above to delete arbitrary Filter Gallery records, including associated filters, image mappings, settings, and details options, by supplying attacker-controlled gallery IDs.
The Filter Gallery plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.1.4. This allows authenticated attackers with subscriber-level access and above to overwrite titles and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.