cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forfilter-gallery filter-gallery

Direction: ascending
Jun 07, 2024

WordPress Filter Gallery Plugin # CVE-2022-4142

CVE, Research URL

CVE-2022-4142

Date
Jan 03, 2023
Research Description
The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.
Affected versions
max 0.1.6.
Status
vulnerable
Jun 16, 2026

WordPress Filter Gallery Plugin # 1b9afc2c-2ad5-4b9a-ba8b-88784a378c8a

Date
-
Research Description
Filter Gallery [filter-gallery] < 0.0.7 Filter Gallery &lt; 0.0.7 - Unauthorised AJAX Calls The plugin had a logic flaw in the CSRF checks of its AJAX calls, allowing them to be passed by not providing the related parameter in the request. This could allow attacker to make logged in users do unwanted actions. Furthermore, the AJAX calls are also lacking capability checks, allowing any authenticated user (such as subscriber) to call them and delete/edit/add arbitrary galleries. Finally, some of the fields were not sanitised before being output in the response, which could also lead to Cross-Site Scripting issues
Affected versions
max 0.0.7.
Status
vulnerable
Sep 19, 2026

WordPress Filter Gallery Plugin # CVE-2026-89138

CVE, Research URL

CVE-2026-89138

Date
Sep 18, 2026
Research Description
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options.
Affected versions
max 1.1.5.
Status
vulnerable

WordPress Filter Gallery Plugin # CVE-2026-89413

CVE, Research URL

CVE-2026-89413

Date
Sep 18, 2026
Research Description
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requires omitting the nonce POST field entirely rather than submitting an invalid value, as a present-but-invalid nonce is correctly rejected.
Affected versions
max 1.1.5.
Status
vulnerable