PT-2026-98392 · WordPress · Modula Image Gallery
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Modula Image Gallery – Photo Grid & Video Gallery versions prior to 3.0.3
Description
Insufficient file path validation in the
upload image() function allows authenticated attackers with author-level access or higher to delete arbitrary files on the server. The restriction to the wp-content/uploads directory is ineffective because all user attachment files are located within that directory, and users with the Author role can easily bypass the edit post check on their own galleries.Recommendations
Update Modula Image Gallery – Photo Grid & Video Gallery to version 3.0.3 or later.
As a temporary mitigation, restrict access to the
upload image() function for users with Author-level permissions.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modula Image Gallery