---
id: CVE-2026-105977
title: >-
  The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform a
  per-object authorization check before deleting an attachment, allowing users
  with the Contributor role and above to permanently delete certain media
  attachmen…
summary: >-
  The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform a
  per-object authorization check before deleting an attachment, allowing users
  with the Contributor role and above to permanently delete certain media
  attachmen…
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:40.427'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105977'
references:
  - url: 'https://wpscan.com/vulnerability/6ad219b8-3633-4c54-a6cf-71cc0acf035e/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.863Z'
---

## Overview

The Portfolio Filter Gallery  WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
