---
id: CVE-2026-105976
title: >-
  The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform
  proper authorization checks in a set of AJAX actions, allowing users with at
  least the Contributor role to read, modify and delete other users' galleries
  as wel…
summary: >-
  The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform
  proper authorization checks in a set of AJAX actions, allowing users with at
  least the Contributor role to read, modify and delete other users' galleries
  as wel…
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:40.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105976'
references:
  - url: 'https://wpscan.com/vulnerability/1ad36801-d53b-4253-ab7a-bd91c0f144f3/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.862Z'
---

## Overview

The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
