CVE-2026-105977: Unknown Portfolio Filter Gallery

Low severity, CVSS 2.2. EPSS: 0.1% chance of exploitation in the next 30 days.

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.

Affected products

  • Unknown Portfolio Filter Gallery: from 2.0.2, before 2.2.1 (fixed in 2.2.1)

Published 2026-10-10. Last modified 2026-10-10.