CVE-2025-62098 - WordPress Portfolio Gallery plugin <= 1.4.8 - broken access control vulnerability

CVE-2025-62098 - WordPress Portfolio Gallery plugin <= 1.4.8 - broken access control vulnerability

CVE ID : CVE-2025-62098 Published : Dec. 31, 2025, 2:47 p.m. | 18 minutes ago Description : Missing Authorization vulnerability in Totalsoft Portfolio Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through 1.4.8. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 31, 2025

Source: Telegram CVE Monitor