Junglewise Threat Intelligence

CVE-2026-89138: WordPress Filter Gallery authorization bypass

CVE-2026-89138 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: Wordpress Filter Gallery. Vendors: Wordpress.

Executive brief

Filter Gallery is a WordPress plugin used to display photo galleries on websites. The plugin fails to properly verify user permissions, allowing authenticated users with basic subscriber accounts to modify posts and gallery settings belonging to other users or the site, potentially disrupting content and affecting site administration.

Technical details

The Filter Gallery plugin for WordPress contains an authorization bypass vulnerability due to insufficient permission checks on sensitive operations. Authenticated attackers with subscriber-level privileges can exploit this flaw to overwrite post titles and content, modify the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options. The vulnerability affects all versions up to and including 1.1.4. The attack requires prior authentication but allows privilege escalation through inadequate capability verification before performing administrative actions.

Affected products

  • WordPress Filter Gallery up to 1.1.4

Timeline

  • 2026-09-18: disclosed

References

Related threats