Description
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requires omitting the nonce POST field entirely rather than submitting an invalid value, as a present-but-invalid nonce is correctly rejected.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Loss / Service Disruption
Action: Apply Patch
AI Analysis

Impact

The Filter Gallery plugin for WordPress allows an authenticated user with subscriber level access or higher to delete any gallery record by providing an arbitrary gallery ID. The deletion removes all associated filters, image mappings, settings, and characteristics, effectively erasing user data and breaking gallery functionality. The vulnerability arises from a missing authorization check and a nonce bypass that requires the nonce field to be omitted entirely. This flaw likely permits the attacker to cause significant loss of content or even interrupt site operation if galleries are essential to the site’s content presentation.

Affected Systems

All installations of the Filter Gallery plugin up to version 1.1.4 on WordPress sites are impacted. The vendor is farazfrank and the product is the Filter Gallery plugin. No specific sub‑versions beyond 1.1.4 are known to be affected, and any newer releases are presumed to contain a fix.

Risk and Exploitability

The vulnerability scores a high CVSS of 8.1 and has an EPSS of less than 1%, indicating a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of reporting. The exploitation path requires the attacker to be authenticated with at least subscriber privileges and to supply a valid gallery ID. The missing authorization check allows the attacker to bypass the normal deletion restrictions and remove gallery data directly, which could lead to data loss and service disruption for sites relying on the plugin.

Generated by OpenCVE AI on September 19, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Filter Gallery plugin to the latest version (1.1.5 or newer) that removes the missing authorization check.
  • If an upgrade is not immediately possible, restrict subscriber users from deleting galleries by removing the delete capability in WordPress role settings or by disabling the deletion action in the plugin’s code or via a custom snippet.
  • Enable logging of gallery deletion actions and monitor for unexpected deletions to detect abuse early.

Generated by OpenCVE AI on September 19, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Farazfrank
Farazfrank filter Gallery
Wordpress
Wordpress wordpress
Vendors & Products Farazfrank
Farazfrank filter Gallery
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requires omitting the nonce POST field entirely rather than submitting an invalid value, as a present-but-invalid nonce is correctly rejected.
Title Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Farazfrank Filter Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:44.393Z

Reserved: 2026-09-11T17:08:50.541Z

Link: CVE-2026-89413

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:00.543Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.337

Modified: 2026-09-18T15:17:17.990

Link: CVE-2026-89413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:49Z

Weaknesses