---
id: CVE-2026-90978
title: >-
  The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on
  several of its AJAX handlers when the nonce field is omitted, and applies no
  capability check, allowing low-privileged users to overwrite the content of
  arbitr…
summary: >-
  The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on
  several of its AJAX handlers when the nonce field is omitted, and applies no
  capability check, allowing low-privileged users to overwrite the content of
  arbitr…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-284
product: Filter Gallery
affected:
  - filter_gallery >= 1.1.2 < 1.1.5
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90978'
references:
  - url: 'https://wpscan.com/vulnerability/39321ecd-98e5-4f4e-9a42-bedf5904c3d1/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00338
epssPercentile: 0.24588
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T11:00:11.604244Z'
ingestedAt: '2026-09-18T06:36:37.988Z'
---

## Overview

The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
