Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-89406— Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters

Quick assessment

Affected
wpchill Modula Image Gallery – Photo Grid & Video Gallery
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“Modula Image Gallery – Photo Grid & Video Gallery”在 3.0.1 及以下版本中存在隐私图库内容未经授权使用者即可查看的漏洞。该问题源于 函数被挂钩到每个前端请求的 中,并通过 查找任意文章(post),而未验证该图库的 或请求者的读取权限。图库侧的输入保护逻辑存在缺陷( 实际上测试的是一个非空的字符串字面量,而非 参数,因此该条件始终为 false),对象验证仅检查 ,并且未执行 或 权限检查。 这使得未认证的攻击者可以枚举私有的 modu

CVSS 7.5 · High EPSS 0.39% · P31
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89406

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters
Source: CVE Program / CVE List V5
Vulnerability Description
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via get_post( $_GET['modula_gallery_id'] ) without verifying the gallery's post_status or the requester's capability to read it — the gallery-side input guard is bugged (empty('modula_gallery_id') tests a nonempty string literal instead of the GET parameter, so it is always false), the only object validation is a post_type === 'modula-gallery' check, and no is_user_logged_in()/current_user_can('read_post', $gallery_id) check is performed. This makes it possible for unauthenticated attackers to enumerate private modula-gallery posts and their member attachments and recover the image's title, description, dimensions, and original upload URL via Open Graph/Twitter meta tags emitted in the response, which then allows direct unauthenticated download of the original private image bytes.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wpchill Modula Image Gallery – Photo Grid & Video Gallery 0 ~ 3.0.1 -

II. Public POCs for CVE-2026-89406

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89406

请登录查看更多情报信息。

News Coverage for CVE-2026-89406 (1)

Other References for CVE-2026-89406 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89406

No comments yet


Leave a comment