PT-2026-109513 · WordPress · Filter Portfolio Gallery

·

CVE-2026-105977

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Portfolio Filter Gallery versions prior to 2.2.1
Description Insufficient per-object authorization checks before deleting attachments allow users with the Contributor role and above to permanently delete media attachments belonging to other users, including administrators. This issue occurs within the pfg delete video thumbnail() function.
Recommendations Update Portfolio Filter Gallery to version 2.2.1 or later. As a temporary workaround, restrict the use of the pfg delete video thumbnail() function for users with the Contributor role.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105977

Affected Products

Filter Portfolio Gallery