Sceawere

Vulnerability Detail

CVE-2026-105976UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Portfolio Filter Gallery Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
8h ago
Vendor
Unknown
Product
Portfolio Filter Gallery
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-10T06:16:40.313Z",
  "pubdate": "2026-10-10T06:16:40.313Z",
  "executiveSummary": "The Portfolio Filter Gallery WordPress plugin prior to version 2.2.1 contains a critical broken access control vulnerability. The flaw stems from insufficient authorization validation within multiple AJAX action handlers. This defect allows authenticated users holding the Contributor role or higher to perform unauthorized administrative operations on gallery content. Attackers can read, modify, and delete galleries created by other users, as well as manipulate site-wide gallery filters. The vulnerability poses a significant risk to site integrity and data confidentiality, as low-privileged users are effectively granted administrative control over the plugin's configuration and content management features. Exploitation does not require elevated privileges beyond the Contributor role, which is typically accessible to untrusted users in many WordPress installations. Successful exploitation could lead to data loss, unauthorized content modification, and potential cross-site scripting vectors if malicious scripts are injected into gallery metadata or filter labels.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of AJAX handlers within the Portfolio Filter Gallery plugin. The plugin fails to implement proper capability checks (using functions like current_user_can()) or utilize nonces to verify that the requesting user has the appropriate authorization level to execute sensitive CRUD (Create, Read, Update, Delete) operations. WordPress AJAX actions registered with the wp_ajax_ prefix are accessible to any logged-in user unless the handler explicitly validates user capabilities.\nThe exploitation flow begins with an authenticated user (with Contributor level or higher) intercepting or crafting an HTTP request directed at the wp-admin/admin-ajax.php endpoint. The attacker identifies the specific action names associated with gallery management, such as those responsible for saving gallery metadata, deleting specific gallery entries, or modifying global filter settings. By supplying the required parameters—such as the target gallery ID or filter ID—in the POST payload, the attacker triggers the backend execution of the insecure function.\nBecause the server-side code does not verify the ownership of the resource being accessed or the administrative rights of the requester, the plugin executes the request on behalf of the attacker. For instance, an attacker can manipulate the primary configuration of a gallery by passing specific values to the update functions, or remove entries entirely by invoking deletion functions. This bypasses the intended multi-user access control model where users should only be permitted to interact with their own galleries.\nThe vulnerability affects all versions of the Portfolio Filter Gallery plugin before 2.2.1. Given that many WordPress plugins rely on standard internal AJAX structures, this vulnerability demonstrates a failure to adhere to the WordPress security guidelines concerning privilege separation. The impact is broad: an attacker can cause denial of service by deleting galleries, sabotage branding by modifying filter names or gallery contents, or perform unauthorized data exfiltration of private or draft gallery configurations. Furthermore, since the input validation for these fields is often minimal, an attacker might attempt to inject persistent malicious payloads into fields that are later rendered on the frontend, potentially escalating the impact to Stored Cross-Site Scripting (XSS) if the plugin does not properly sanitize the database entries during the save process."
}
CVE-2026-105976: Portfolio Filter Gallery Authorization Bypass (MEDIUM Severity, CVSS: 4.7) | Sceawere