Impact
The Filter Gallery plugin contains a missing authorization check in the ufg_save_gallery AJAX action. Because the plugin does not verify that a user is allowed to perform this action, authenticated users with subscriber-level permissions or higher can manipulate arbitrary WordPress posts. Attackers can overwrite a post’s title and content, set the _wp_attachment_image_alt meta key, and create or alter ufg_gallery_* options, which can lead to defacement or content injection. The flaw is classified as Missing Authorization (CWE-862).
Affected Systems
Any WordPress site that has the farazfrank Filter Gallery plugin installed in a version numbered 1.1.4 or earlier is vulnerable. The issue applies to all installations of the plugin regardless of theme or other plugins, and there is no restriction on which posts can be targeted beyond those readable or editable by the subsequently authenticated role.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity, and the EPSS score is under 1%, showing a low probability of exploitation at the time of assessment. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector requires an authenticated session and leverages a standard AJAX call, so an attacker must first log in with at least subscriber privileges. Once authenticated, the attacker can exploit the vulnerability to modify content, but the risk depends heavily on the site’s content and the attacker’s intent. Because the exploit does not require elevated privileges beyond the legitimate role level, it is likely to be used in targeted defacement or information disclosure scenarios rather than widespread automated attacks.
OpenCVE Enrichment