rootpwn

high · CVSS v3 8.1 · EPSS 0.0029

CVE-2026-89413

The Filter Gallery plugin for WordPress allows any authenticated user with subscriber-level access to delete arbitrary gallery records due t

Overview

The Filter Gallery plugin for WordPress allows any authenticated user with subscriber-level access to delete arbitrary gallery records due to an authorization bypass. This can result in loss of content, settings, and image mappings. The flaw exists in all versions up to and including 1.1.4.

Description

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requires omitting the nonce POST field entirely rather than submitting an invalid value, as a present-but-invalid nonce is correctly rejected.

Impact

Integrity and availability of gallery data are compromised, leading to loss of content and configuration. Site administrators and owners are directly impacted, as well as any users relying on the galleries for display or functionality.

Remediation

Update the Filter Gallery plugin to version 1.1.5 or later where the authorization check is fixed. If an update is not immediately possible, remove the plugin or restrict subscriber-level users from accessing gallery management. Monitor audit logs for unauthorized delete actions and consider disabling the delete capability via role management.

Risk context

The vulnerability is rated high severity (CVSS 8.1) but has a low EPSS score of 0.0029, indicating a low likelihood of exploitation in the wild. Nonetheless, the potential impact warrants prompt attention.

Affected products

  • WordPress Filter Gallery <=1.1.4

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.1
CVSS v4
EPSS
0.0029

WordPress Filter Gallery Authorization Bypass Subscriber Data Loss Integrity Availability High Severity

← All CVEs