Sceawere
Vulnerability Detail
CVE-2026-105977UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Portfolio Filter Gallery Insecure Authorization
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.2
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Portfolio Filter Gallery
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.2",
"pubDate": "2026-10-10T06:16:40.427Z",
"pubdate": "2026-10-10T06:16:40.427Z",
"executiveSummary": "The Portfolio Filter Gallery WordPress plugin prior to version 2.2.1 contains an insecure direct object reference (IDOR) vulnerability related to attachment management.\nThe vulnerability allows authenticated users with the Contributor role or higher to trigger the deletion of media attachments that they do not own, including those uploaded by administrative users.\nThis flaw stems from a failure to perform adequate per-object authorization checks during the deletion request handling process.\nAn attacker possessing low-level credentials can leverage this flaw to perform unauthorized data destruction, impacting the integrity and availability of site media assets.\nThe vulnerability does not require administrative privileges to initiate, posing a significant risk to content management security within WordPress installations utilizing the plugin.",
"technicalDetails": "The vulnerability originates from the plugin's failure to enforce strict ownership verification when processing attachment deletion requests. In WordPress, media attachments are posts of the 'attachment' type, and standard security practices dictate that sensitive operations—such as permanent deletion—must verify the 'edit_post' capability for the specific post ID provided in the request.\nThe root cause is an improper authorization check within the plugin's request handling logic. When a deletion request is intercepted, the plugin fails to validate whether the authenticated user has the necessary permissions to delete the specific media object referenced by the ID. Instead, the plugin assumes that if a user is authenticated with a minimum role of 'Contributor', they are authorized to invoke the deletion routine, ignoring the actual ownership metadata of the attachment.\nExploitation follows a predictable attack flow: 1. An attacker with a Contributor-level account identifies the Media ID (attachment ID) of a target file, which is often discoverable via the WordPress Media Library interface or existing page source code. 2. The attacker crafts a request to the plugin's deletion endpoint, supplying the target attachment ID. 3. The server-side code receives the request and proceeds to execute the 'wp_delete_attachment' function (or an equivalent) without verifying if the requesting user is the original author or holds the 'delete_posts' capability for that specific attachment. 4. WordPress executes the deletion routine, permanently removing the media file from the file system and the database entries.\nBecause the plugin does not enforce per-object authorization, the impact is privilege escalation in terms of functional scope; a user limited by the WordPress core capability system to only manage their own files can effectively delete files belonging to other users or site administrators. This can lead to unauthorized data loss, site disruption, and potential information integrity compromises if critical images or documents required for site functionality are purged. The vulnerability is restricted to authenticated sessions and does not allow for remote code execution, but it represents a critical failure in access control policy enforcement within the plugin architecture."
}