PT-2026-98392 · WordPress · Modula Image Gallery

·

CVE-2026-92713

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Modula Image Gallery – Photo Grid & Video Gallery versions prior to 3.0.3
Description Insufficient file path validation in the upload image() function allows authenticated attackers with author-level access or higher to delete arbitrary files on the server. The restriction to the wp-content/uploads directory is ineffective because all user attachment files are located within that directory, and users with the Author role can easily bypass the edit post check on their own galleries.
Recommendations Update Modula Image Gallery – Photo Grid & Video Gallery to version 3.0.3 or later. As a temporary mitigation, restrict access to the upload image() function for users with Author-level permissions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92713

Affected Products

Modula Image Gallery