CVE-2026-105977: Unknown Portfolio Filter Gallery
Low severity, CVSS 2.2. EPSS: 0.1% chance of exploitation in the next 30 days.
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.
Affected products
- Unknown Portfolio Filter Gallery: from 2.0.2, before 2.2.1 (fixed in 2.2.1)
Published 2026-10-10. Last modified 2026-10-10.