CVE-2026-90978: Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check

Published Sep 18, 2026
·
Updated

The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.

Affected Software

1 affected component
WordPress Filter Gallery<1.1.5

Event History

Sep 18, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with a low-privileged account, including a Subscriber-level account, can exploit it. No higher WordPress capability check is applied by the affected AJAX handlers.

2

What does an attacker need to do to bypass the nonce protection?

The attacker can omit the nonce field from requests to the affected AJAX handlers. In affected versions, the handlers fail open when that field is absent rather than rejecting the request.

3

What impact should administrators investigate?

An attacker may overwrite the content of arbitrary posts and delete stored Filter Gallery gallery options. Review post content for unauthorized changes and check whether the plugin's gallery configuration or options have been removed.

4

Which installations are affected?

Filter Gallery versions before 1.1.5 are affected. Installations where untrusted or low-privileged users can authenticate to WordPress have a direct exposure path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203