Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 20 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Farazfrank
Farazfrank filter Gallery Wordpress Wordpress wordpress |
|
| Vendors & Products |
Farazfrank
Farazfrank filter Gallery Wordpress Wordpress wordpress |
Fri, 18 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requires omitting the nonce POST field entirely rather than submitting an invalid value, as a present-but-invalid nonce is correctly rejected. | |
| Title | Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-18T14:31:44.393Z
Reserved: 2026-09-11T17:08:50.541Z
Link: CVE-2026-89413
Updated: 2026-09-18T14:30:00.543Z
Status : Deferred
Published: 2026-09-18T07:16:51.337
Modified: 2026-09-18T15:17:17.990
Link: CVE-2026-89413
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:30:49Z