{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressfilter_gallery/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:filter_gallery:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-89413"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Filter Gallery (\u003c= 1.1.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Filter Gallery plugin for WordPress is affected by an authorization bypass vulnerability, tracked as CVE-2026-89413, impacting all versions up to and including 1.1.4. The flaw originates from the plugin's failure to enforce adequate authorization checks when performing administrative actions. Consequently, any authenticated user with at least subscriber-level permissions can trigger the deletion of arbitrary gallery records, including associated image mappings, configurations, and metadata.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is specifically characterized by an improper nonce validation mechanism. Attackers can bypass this security control by omitting the nonce field entirely in the HTTP POST request; the plugin incorrectly processes the request as valid when the field is absent, whereas it properly rejects requests containing an incorrect or malformed nonce. This vulnerability allows for unauthorized data destruction within the WordPress environment, potentially impacting site functionality and content management workflows.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains a valid WordPress user account with at least subscriber-level privileges via self-registration or compromised credentials.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the WordPress administrative interface or interacts directly with the site's REST API/admin-ajax endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the specific target gallery IDs by enumerating accessible gallery resources or guessing integer sequences.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP POST request targeting the Filter Gallery deletion endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker explicitly omits the expected 'nonce' parameter from the POST body to bypass the plugin's security verification.\u003c/li\u003e\n\u003cli\u003eThe web server passes the request to the vulnerable plugin, which fails to validate the user's authorization and the presence of the nonce.\u003c/li\u003e\n\u003cli\u003eThe plugin executes the deletion operation for the specified gallery record within the WordPress database.\u003c/li\u003e\n\u003cli\u003eThe targeted gallery, including its associated filters and image mappings, is permanently removed.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows low-privileged attackers to perform unauthorized destructive actions against gallery data. Victims face the loss of all image mappings, custom settings, and filter configurations associated with the targeted galleries, requiring manual restoration from backups. This vulnerability affects any WordPress site running Filter Gallery version 1.1.4 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all WordPress installations currently utilizing the 'Filter Gallery' plugin.\u003c/li\u003e\n\u003cli\u003ePatch the plugin to the version that remediates CVE-2026-89413 immediately upon availability.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed at plugin-specific administrative endpoints lacking standard security tokens.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized user activity originating from subscriber-level accounts that perform bulk deletion of content or database records.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T08:04:36Z","date_published":"2026-09-18T08:04:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-filter-gallery-auth-bypass/","summary":"The Filter Gallery WordPress plugin contains an authorization bypass vulnerability (CVE-2026-89413) allowing authenticated users with low-level privileges to delete arbitrary gallery records by omitting mandatory nonce checks.","title":"Authorization Bypass in WordPress Filter Gallery Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-filter-gallery-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:filter_gallery:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}