CVE-2026-105976: Unknown Portfolio Filter Gallery

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.

Affected products

  • Unknown Portfolio Filter Gallery: before 2.2.1 (fixed in 2.2.1)

Published 2026-10-10. Last modified 2026-10-10.