CVE-2026-105976
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 10, 2026
Vendor
unknown
Description
The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.