Description
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Post Modification
Action: Apply Patch
AI Analysis

Impact

The Filter Gallery plugin contains a missing authorization check in the ufg_save_gallery AJAX action. Because the plugin does not verify that a user is allowed to perform this action, authenticated users with subscriber-level permissions or higher can manipulate arbitrary WordPress posts. Attackers can overwrite a post’s title and content, set the _wp_attachment_image_alt meta key, and create or alter ufg_gallery_* options, which can lead to defacement or content injection. The flaw is classified as Missing Authorization (CWE-862).

Affected Systems

Any WordPress site that has the farazfrank Filter Gallery plugin installed in a version numbered 1.1.4 or earlier is vulnerable. The issue applies to all installations of the plugin regardless of theme or other plugins, and there is no restriction on which posts can be targeted beyond those readable or editable by the subsequently authenticated role.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate severity, and the EPSS score is under 1%, showing a low probability of exploitation at the time of assessment. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector requires an authenticated session and leverages a standard AJAX call, so an attacker must first log in with at least subscriber privileges. Once authenticated, the attacker can exploit the vulnerability to modify content, but the risk depends heavily on the site’s content and the attacker’s intent. Because the exploit does not require elevated privileges beyond the legitimate role level, it is likely to be used in targeted defacement or information disclosure scenarios rather than widespread automated attacks.

Generated by OpenCVE AI on September 19, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Filter Gallery to the latest version that resolves the authorization check, which follows the 1.1.4 release; if an update is available, apply it immediately.
  • If an upgrade is not possible, remove or block the ufg_save_gallery AJAX endpoint by editing the plugin’s main file or by adding a custom function that unhooks the action during plugin initialization.
  • Revoke the capability that allows subscriber-level users to edit posts (e.g., 'edit_posts') or otherwise reduce their privileges by adjusting role capabilities so that they can no longer trigger the vulnerable action.

Generated by OpenCVE AI on September 19, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Farazfrank
Farazfrank filter Gallery
Wordpress
Wordpress wordpress
Vendors & Products Farazfrank
Farazfrank filter Gallery
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.
Title Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'image_id' Parameter via ufg_save_gallery AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Farazfrank Filter Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:43.226Z

Reserved: 2026-09-10T22:55:45.434Z

Link: CVE-2026-89138

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:44.922Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:50.907

Modified: 2026-09-18T15:17:17.767

Link: CVE-2026-89138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:39Z

Weaknesses