Impact
The Filter Gallery plugin for WordPress allows an authenticated user with subscriber level access or higher to delete any gallery record by providing an arbitrary gallery ID. The deletion removes all associated filters, image mappings, settings, and characteristics, effectively erasing user data and breaking gallery functionality. The vulnerability arises from a missing authorization check and a nonce bypass that requires the nonce field to be omitted entirely. This flaw likely permits the attacker to cause significant loss of content or even interrupt site operation if galleries are essential to the site’s content presentation.
Affected Systems
All installations of the Filter Gallery plugin up to version 1.1.4 on WordPress sites are impacted. The vendor is farazfrank and the product is the Filter Gallery plugin. No specific sub‑versions beyond 1.1.4 are known to be affected, and any newer releases are presumed to contain a fix.
Risk and Exploitability
The vulnerability scores a high CVSS of 8.1 and has an EPSS of less than 1%, indicating a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of reporting. The exploitation path requires the attacker to be authenticated with at least subscriber privileges and to supply a valid gallery ID. The missing authorization check allows the attacker to bypass the normal deletion restrictions and remove gallery data directly, which could lead to data loss and service disruption for sites relying on the plugin.
OpenCVE Enrichment