Authorization Bypass in Filter Gallery Plugin for WordPress
CVE-2026-89413
What is CVE-2026-89413?
The Filter Gallery plugin for WordPress contains an authorization bypass vulnerability that affects all versions up to and including 1.1.4. This flaw arises because the plugin fails to properly verify whether a user has the necessary permissions to execute certain actions. As a result, authenticated attackers with subscriber-level access or higher can exploit this weakness to delete any arbitrary Filter Gallery records, including all associated filters, image mappings, settings, and details, simply by providing attacker-controlled gallery IDs. Notably, the nonce bypass is achieved by omitting the nonce POST field, as a present-but-invalid nonce is rejected correctly, thereby allowing attackers to manipulate records freely.
Affected Version(s)
Filter Gallery 0 <= 1.1.4