CVE-2026-90978
Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
| Vendor | unknown |
| Product | filter gallery |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown filter gallery
Be the first to know when new unknown vulnerabilities affecting unknown filter gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Filter Gallery
1.1.2 < 1.1.5
References
Credits
Seongwon Lee WPScan