Sceawere

Vulnerability Detail

CVE-2026-105977UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Portfolio Filter Gallery Insecure Authorization

Vulnerability Metadata

Severity
Low
Score / CVSS
2.2
Creation Date
8h ago
Vendor
Unknown
Product
Portfolio Filter Gallery
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.2",
  "pubDate": "2026-10-10T06:16:40.427Z",
  "pubdate": "2026-10-10T06:16:40.427Z",
  "executiveSummary": "The Portfolio Filter Gallery WordPress plugin prior to version 2.2.1 contains an insecure direct object reference (IDOR) vulnerability related to attachment management.\nThe vulnerability allows authenticated users with the Contributor role or higher to trigger the deletion of media attachments that they do not own, including those uploaded by administrative users.\nThis flaw stems from a failure to perform adequate per-object authorization checks during the deletion request handling process.\nAn attacker possessing low-level credentials can leverage this flaw to perform unauthorized data destruction, impacting the integrity and availability of site media assets.\nThe vulnerability does not require administrative privileges to initiate, posing a significant risk to content management security within WordPress installations utilizing the plugin.",
  "technicalDetails": "The vulnerability originates from the plugin's failure to enforce strict ownership verification when processing attachment deletion requests. In WordPress, media attachments are posts of the 'attachment' type, and standard security practices dictate that sensitive operations—such as permanent deletion—must verify the 'edit_post' capability for the specific post ID provided in the request.\nThe root cause is an improper authorization check within the plugin's request handling logic. When a deletion request is intercepted, the plugin fails to validate whether the authenticated user has the necessary permissions to delete the specific media object referenced by the ID. Instead, the plugin assumes that if a user is authenticated with a minimum role of 'Contributor', they are authorized to invoke the deletion routine, ignoring the actual ownership metadata of the attachment.\nExploitation follows a predictable attack flow: 1. An attacker with a Contributor-level account identifies the Media ID (attachment ID) of a target file, which is often discoverable via the WordPress Media Library interface or existing page source code. 2. The attacker crafts a request to the plugin's deletion endpoint, supplying the target attachment ID. 3. The server-side code receives the request and proceeds to execute the 'wp_delete_attachment' function (or an equivalent) without verifying if the requesting user is the original author or holds the 'delete_posts' capability for that specific attachment. 4. WordPress executes the deletion routine, permanently removing the media file from the file system and the database entries.\nBecause the plugin does not enforce per-object authorization, the impact is privilege escalation in terms of functional scope; a user limited by the WordPress core capability system to only manage their own files can effectively delete files belonging to other users or site administrators. This can lead to unauthorized data loss, site disruption, and potential information integrity compromises if critical images or documents required for site functionality are purged. The vulnerability is restricted to authenticated sessions and does not allow for remote code execution, but it represents a critical failure in access control policy enforcement within the plugin architecture."
}
CVE-2026-105977: Portfolio Filter Gallery Insecure Authorization (LOW Severity, CVSS: 2.2) | Sceawere