๐Ÿ” CVE Alert

CVE-2026-90978

UNKNOWN 0.0

Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.

Vendor unknown
Product filter gallery
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown filter gallery

Be the first to know when new unknown vulnerabilities affecting unknown filter gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Filter Gallery
1.1.2 < 1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/39321ecd-98e5-4f4e-9a42-bedf5904c3d1/

Credits

Seongwon Lee WPScan