The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.
https://wpscan.com/vulnerability/1ad36801-d53b-4253-ab7a-bd91c0f144f3/