Modula Image Gallery – Photo Grid & Video Gallery 2.14.25-2.14.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.14.25-2.14.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arb...
- CVSS:
- 6.4
- Affected:
- 2.14.25 – 2.14.30
- Fixed in:
- 2.14.31
- Disclosed:
- Jul 22, 2026
CVE-2026-65475 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.23 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.14.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inj...
- CVSS:
- 6.4
- Affected:
- up to 2.14.23
- Fixed in:
- 2.14.24
- Disclosed:
- May 26, 2026
CVE-2026-42688 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 - Authenticated (Author+) PHP Object Injection
high
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.14.18 via deserialization of untrusted input. This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP...
- CVSS:
- 7.5
- Affected:
- up to 2.14.18
- Fixed in:
- 2.14.19
- Disclosed:
- Apr 20, 2026
CVE-2026-39481 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing
medium
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. This makes it possible...
- CVSS:
- 4.3
- Affected:
- up to 2.13.6
- Fixed in:
- 2.13.7
- Disclosed:
- Feb 13, 2026
CVE-2026-1254 on NVD →
Modula Image Gallery <= 2.13.4 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.5
- Disclosed:
- Feb 4, 2026
CVE-2026-23976 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] <= 2.13.6 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through <= 2.13.6.
- Affected:
- up to 2.13.6
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24939 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] <= 2.13.4 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4.
- Affected:
- up to 2.13.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-23976 on NVD →
Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification
medium
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Author-level...
- CVSS:
- 4.3
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.4
- Disclosed:
- Dec 15, 2025
CVE-2025-14003 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.13.4
unknown
[en] The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Author-l...
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.4
- Disclosed:
- Dec 15, 2025
CVE-2025-14003 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.13.4
unknown
[en] The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endpoint verifies user capabilities (Au...
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.4
- Disclosed:
- Dec 12, 2025
CVE-2025-13891 on NVD →
Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing
medium
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endpoint verifies user capabilities (Author+...
- CVSS:
- 6.5
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.4
- Disclosed:
- Dec 11, 2025
CVE-2025-13891 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.13.3
unknown
[en] The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condi...
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.3
- Disclosed:
- Dec 3, 2025
CVE-2025-13646 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.13.3
unknown
[en] The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the se...
- Affected:
- up to 2.13.3
- Fixed in:
- 2.13.3
- Disclosed:
- Dec 3, 2025
CVE-2025-13645 on NVD →
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
high
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condition...
- CVSS:
- 7.5
- Affected:
- 2.13.1 – 2.13.2
- Fixed in:
- 2.13.3
- Disclosed:
- Dec 2, 2025
CVE-2025-13646 on NVD →
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
high
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server,...
- CVSS:
- 7.2
- Affected:
- 2.13.1 – 2.13.2
- Fixed in:
- 2.13.3
- Disclosed:
- Dec 2, 2025
CVE-2025-13645 on NVD →
Modula Image Gallery <= 2.13.6 - Missing Authorization
medium
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.13.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthor...
- CVSS:
- 4.3
- Affected:
- up to 2.13.6
- Fixed in:
- 2.13.7
- Disclosed:
- Nov 22, 2025
CVE-2026-24939 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.12.29
unknown
[en] The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and abov...
- Affected:
- up to 2.12.29
- Fixed in:
- 2.12.29
- Disclosed:
- Nov 15, 2025
CVE-2025-12494 on NVD →
Image Gallery – Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move
medium
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 2.12.28
- Fixed in:
- 2.12.29
- Disclosed:
- Nov 14, 2025
CVE-2025-12494 on NVD →
Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library
medium
The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributo...
- CVSS:
- 6.4
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.2
- Disclosed:
- Apr 2, 2025
CVE-2024-9416 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.11.11
unknown
[en] The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files...
- Affected:
- up to 2.11.11
- Fixed in:
- 2.11.11
- Disclosed:
- Jan 8, 2025
CVE-2024-12853 on NVD →
Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload
high
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on th...
- CVSS:
- 8.8
- Affected:
- up to 2.11.10
- Fixed in:
- 2.11.11
- Disclosed:
- Jan 7, 2025
CVE-2024-12853 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.7.5
unknown
Update the WordPress Modula Image Gallery plugin to the latest available version (at least 2.7.5).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress Modula Image Gallery Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a...
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Sep 12, 2023
Modula <= 2.7.4 - Incomplete Authorization via 'save_image' and 'save_images'
low
The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check on the 'save_image' and 'save_images' functions in versions up to, and including, 2.7.4. This makes it possible for authenticated attackers with the 'edit_others_posts' but not the 'edit_posts' capab...
- CVSS:
- 2.2
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Sep 10, 2023
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.7.5
unknown
The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check on the 'save_image' and 'save_images' functions in versions up to, and including, 2.7.4. This makes it possible for authenticated attackers with the 'edit_others_posts' but not the 'edit_posts' capab...
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Sep 10, 2023
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.6.91
unknown
[en] Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
- Affected:
- up to 2.6.91
- Fixed in:
- 2.6.91
- Disclosed:
- Nov 18, 2022
CVE-2022-41135 on NVD →
Customizable WordPress Gallery Plugin – Modula Image Gallery <= 2.6.9 - Missing Authorization to Plugin Settings Change
high
The Customizable WordPress Gallery Plugin – Modula Image Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the update_troubleshooting_options function in versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to update some of the...
- CVSS:
- 7.5
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.91
- Disclosed:
- Oct 28, 2022
CVE-2022-41135 on NVD →
Modula Image Gallery <= 2.6.6 - Reflected Cross-Site Scripting
medium
The Modula Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 6, 2022
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.6.7
unknown
The Modula Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 6, 2022
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.6.7
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Modula Image Gallery plugin (versions <= 2.6.6).
Update the WordPress Modula Image Gallery plugin to the latest available version (at least 2.6.7).
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 6, 2022
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.2.5
unknown
[en] A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Feb 20, 2020
CVE-2020-9003 on NVD →
Modula Image Gallery <= 2.2.4 - Authenticated Stored Cross-Site Scripting
medium
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
- CVSS:
- 6.4
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Feb 19, 2020
CVE-2020-9003 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.10.2
unknown
- Affected:
- up to 2.10.2
- Fixed in:
- 2.10.2
CVE-2024-9416 on NVD →
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.7.5
unknown
The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check on the 'save_image' and 'save_images' functions in versions up to, and including, 2.7.4. This makes it possible for authenticated attackers with the 'edit_others_posts'...
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] < 2.6.7
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7