PT-2026-98388 · WordPress · Modula Image Gallery

·

CVE-2026-89406

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Modula Image Gallery – Photo Grid & Video Gallery versions prior to 3.0.2
Description Unauthenticated attackers can cause the unauthorized disclosure of private gallery contents. The issue occurs because the Modula Meta::add metas() function is hooked to wp head on every frontend request and retrieves posts using the modula gallery id parameter via get post() without verifying the post status or the requester's permissions. A bug in the input guard causes empty('modula gallery id') to test a string literal instead of the actual GET parameter, rendering the check ineffective. Consequently, attackers can enumerate private gallery posts and their attachments to recover image titles, descriptions, dimensions, and original upload URLs through Open Graph and Twitter meta tags, enabling the direct download of private image bytes.
Recommendations Update the plugin to a version newer than 3.0.1.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89406

Affected Products

Modula Image Gallery