The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Filter Gallery WordPress plugin before version 1.1.5 contains a critical authorization vulnerability in its AJAX handlers. When a nonce field is omitted from requests, the plugin fails to verify the nonce token and does not check user capabilities, allowing low-privileged users (including subscribers or unauthenticated users depending on WordPress configuration) to perform privileged actions. This vulnerability enables attackers to arbitrarily overwrite the content of any post and delete stored gallery options, potentially leading to data destruction, website defacement, and loss of gallery configurations. WordPress sites relying on this plugin for image gallery functionality are directly at risk, particularly those with numerous contributors or public-facing content.
While this CVE maps to CWE-284 (Improper Access Control), it reflects attack patterns consistent with MITRE ATT&CK techniques like T1190 (Exploit Public-Facing Application) and T1190-derived post-exploitation activities. Casky.ai's extended reasoning capabilities across 754 security skills would detect this vulnerability by identifying suspicious AJAX request patterns that lack proper nonce validation, abnormal post modification requests from low-privilege accounts, and unauthorized capability execution in WordPress logs. A practitioner using Casky would surface findings indicating repeated failed nonce checks, capability bypass attempts in AJAX handlers, and bulk content modifications originating from unexpected user roles—patterns that indicate exploitation of authorization controls before they escalate to active compromise.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90978. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation