Executive brief
The Filter Gallery WordPress plugin fails to properly authorize users before allowing deletion of gallery records. An attacker with a basic subscriber account can delete any gallery and its associated filters, images, and settings by submitting a specially crafted request that bypasses the plugin's nonce verification mechanism, causing permanent data loss.
Technical details
The vulnerability is an authorization bypass flaw in the Filter Gallery WordPress plugin affecting versions up to 1.1.4. The plugin fails to properly validate user authorization and has a nonce bypass vulnerability that can be exploited by omitting the nonce POST field entirely rather than submitting an invalid value. Authenticated attackers with subscriber-level privileges or higher can delete arbitrary gallery records by supplying attacker-controlled gallery IDs. The attack is network-accessible to any authenticated user and requires no additional interaction. An attacker can achieve complete deletion of gallery data, filters, image mappings, and associated settings.
Affected products
- Filter Gallery Filter Gallery up to 1.1.4
Timeline
- 2026-09-18: disclosed