PT-2026-109513 · WordPress · Filter Portfolio Gallery
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Portfolio Filter Gallery versions prior to 2.2.1
Description
Insufficient per-object authorization checks before deleting attachments allow users with the Contributor role and above to permanently delete media attachments belonging to other users, including administrators. This issue occurs within the
pfg delete video thumbnail() function.Recommendations
Update Portfolio Filter Gallery to version 2.2.1 or later.
As a temporary workaround, restrict the use of the
pfg delete video thumbnail() function for users with the Contributor role.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filter Portfolio Gallery