Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPChill — Vulnerabilities & Security Advisories 66

Browse all 66 CVE security advisories affecting WPChill. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPChill operates as a developer of premium WordPress plugins, primarily focusing on e-commerce solutions, membership management, and digital product delivery. Security audits reveal a concerning history, with 57 recorded Common Vulnerabilities and Exposures (CVEs) associated with its software portfolio. These vulnerabilities predominantly stem from insufficient input validation and inadequate access controls, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. Many flaws allow unauthenticated attackers to execute arbitrary code or manipulate administrative functions, highlighting systemic weaknesses in code review processes. While the company provides technical support, the high volume of disclosed CVEs suggests a reactive rather than proactive security posture. Users of WPChill products face significant risk, necessitating rigorous patch management and continuous monitoring to mitigate potential exploitation of these historically common attack vectors.

Found 8 results / 66 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-89406 Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 7.5 High 2026-09-25
CVE-2026-92713 Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 8.1 High 2026-09-25
CVE-2026-1254 Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 4.3 Medium 2026-02-14
CVE-2025-14003 Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 4.3 Medium 2025-12-15
CVE-2025-13891 Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing — Modula Image Gallery – Photo Grid & Video Gallery CWE-22 6.5 Medium 2025-12-12
CVE-2025-12494 Image Gallery – Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move — Modula Image Gallery – Photo Grid & Video Gallery CWE-285 4.3 Medium 2025-11-15
CVE-2024-9416 Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library — Modula Image Gallery – Photo Grid & Video Gallery CWE-79 6.4 Medium 2025-04-03
CVE-2024-12853 Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload — Modula Image Gallery – Photo Grid & Video Gallery CWE-434 8.8 High 2025-01-08

This page lists every published CVE security advisory associated with WPChill. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.