CVE-2026-105976: Unknown Portfolio Filter Gallery
Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.
Affected products
- Unknown Portfolio Filter Gallery: before 2.2.1 (fixed in 2.2.1)
Published 2026-10-10. Last modified 2026-10-10.