{"id":"CVE-2026-105976","title":"The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as wel…","summary":"The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as wel…","severity":"none","published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T06:16:40.313","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105976","references":[{"url":"https://wpscan.com/vulnerability/1ad36801-d53b-4253-ab7a-bd91c0f144f3/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T06:24:42.862Z","slug":"CVE-2026-105976","body":"## Overview\n\nThe Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}