The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators. This vulnerability can disrupt content management on WordPress sites, particularly those with multiple contributors o [truncated]
ReviewPortfolio Filter GalleryCVE published 2026-10-10
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters. This vulnerability allows Contributor+ users to potentially modify or delete galleries and filters without proper authorization, which could [truncated]