Extension WordPress

Vulnérabilités Modula Image Gallery – Photo Grid & Video Gallery

Cette page rassemble les failles publiées pour Modula Image Gallery – Photo Grid & Video Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
0Critiques
16Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Modula Image Gallery – Photo Grid & Video Gallery

16 fiches

CVE-2026-42688 Moyenne · 6,4
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.23 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.14.23 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.14.23

Correctif

2.14.24

Publication

26/05/2026

CVE-2026-39481 Élevée · 7,5
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 – Authenticated (Author+) PHP Object Injection

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.14.18 via deserialization of untrusted input. This makes it possible for authenticated attackers,…

Versions affectées

*-2.14.18

Correctif

2.14.19

Publication

20/04/2026

CVE-2026-1254 Moyenne · 4,3
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 – Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user…

Versions affectées

*-2.13.6

Correctif

2.13.7

Publication

13/02/2026

CVE-2026-23976 Moyenne · 6,4
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery <= 2.13.4 – Authenticated (Author+) Stored Cross-Site Scripting

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access…

Versions affectées

*-2.13.4

Correctif

2.13.5

Publication

04/02/2026

CVE-2025-14003 Moyenne · 4,3
Modula Image Gallery – Photo Grid & Video Gallery

Image Gallery – Photo Grid & Video Gallery <= 2.13.3 – Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This…

Versions affectées

*-2.13.3

Correctif

2.13.4

Publication

15/12/2025

CVE-2025-13891 Moyenne · 6,5
Modula Image Gallery – Photo Grid & Video Gallery

Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 – Missing Authorization to Arbitrary Directory Listing

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation…

Versions affectées

*-2.13.3

Correctif

2.13.4

Publication

11/12/2025

CVE-2025-13646 Élevée · 7,5
Modula Image Gallery – Photo Grid & Video Gallery

Modula 2.13.1 – 2.13.2 – Authenticated (Author+) Arbitrary File Upload via Race Condition

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access…

Versions affectées

2.13.1-2.13.2

Correctif

2.13.3

Publication

02/12/2025

CVE-2025-13645 Élevée · 7,2
Modula Image Gallery – Photo Grid & Video Gallery

Modula 2.13.1 – 2.13.2 – Authenticated (Author+) Arbitrary File Deletion

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access…

Versions affectées

2.13.1-2.13.2

Correctif

2.13.3

Publication

02/12/2025

CVE-2025-12494 Moyenne · 4,3
Modula Image Gallery – Photo Grid & Video Gallery

Image Gallery – Photo Grid & Video Gallery <= 2.12.28 – Improper Authorization to Authenticated (Author+) Arbitrary Image File Move

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes…

Versions affectées

*-2.12.28

Correctif

2.12.29

Publication

14/11/2025

CVE-2024-12853 Élevée · 8,8
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery <= 2.11.10 – Authenticated (Author+) Arbitrary File Upload

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated…

Versions affectées

*-2.11.10

Correctif

2.11.11

Publication

07/01/2025

Vulnérabilité Faible · 2,2
Modula Image Gallery – Photo Grid & Video Gallery

Modula <= 2.7.4 – Incomplete Authorization via 'save_image' and 'save_images'

The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check on the 'save_image' and 'save_images' functions in versions up to, and including, 2.7.4. This makes it possible for authenticated attackers…

Versions affectées

[*, 2.7.5)

Correctif

2.7.5

Publication

10/09/2023

CVE-2022-41135 Élevée · 7,5
Modula Image Gallery – Photo Grid & Video Gallery

Customizable WordPress Gallery Plugin – Modula Image Gallery <= 2.6.9 – Missing Authorization to Plugin Settings Change

The Customizable WordPress Gallery Plugin – Modula Image Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the update_troubleshooting_options function in versions up to, and including, 2.6.9. This makes it possible…

Versions affectées

*-2.6.9

Correctif

2.6.91

Publication

28/10/2022

CVE-2020-9003 Moyenne · 6,4
Modula Image Gallery – Photo Grid & Video Gallery

Modula Image Gallery <= 2.2.4 – Authenticated Stored Cross-Site Scripting

A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.

Versions affectées

[*, 2.2.5)

Correctif

2.2.5

Publication

19/02/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités