Plugin Vulnerability Hub
Plugin 15 known issues Latest disclosed Apr 20, 2026

Modula Image Gallery – Photo Grid & Video Gallery Vulnerabilities

Review known vulnerability records for the WordPress plugin Modula Image Gallery – Photo Grid & Video Gallery (`modula-best-grid-gallery`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-39481, CVE-2026-1254 and CVE-2026-23976, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
15
High or Critical
5
Patch Coverage
100%
Last Updated
Apr 30, 2026
Priority CVE Quick Links

Fast paths into Modula Image Gallery – Photo Grid & Video Gallery CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
13
CVE-2024-12853 High 2.11.11
CVE-2024-12853 Modula Image Gallery – Photo Grid & Video Gallery Remote Code Execution

Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload

CVE-2026-39481 High 2.14.19
CVE-2026-39481 Modula Image Gallery – Photo Grid & Video Gallery Vulnerability

Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 - Authenticated (Author+) PHP Object Injection

CVE-2025-13646 High 2.13.3
CVE-2025-13646 Modula Image Gallery – Photo Grid & Video Gallery Remote Code Execution

Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition

CVE-2022-41135 High 2.6.91
CVE-2022-41135 Modula Image Gallery – Photo Grid & Video Gallery Authorization Bypass

Customizable WordPress Gallery Plugin – Modula Image Gallery <= 2.6.9 - Missing Authorization to Plugin Settings Change

CVE-2025-13645 High 2.13.3
CVE-2025-13645 Modula Image Gallery – Photo Grid & Video Gallery Remote Code Execution

Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion

CVE-2025-13891 Medium 2.13.4
CVE-2025-13891 Modula Image Gallery – Photo Grid & Video Gallery Vulnerability

Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing

CVE-2026-23976 Medium 2.13.5
CVE-2026-23976 Modula Image Gallery – Photo Grid & Video Gallery Stored Cross-Site Scripting

Modula Image Gallery <= 2.13.4 - Authenticated (Author+) Stored Cross-Site Scripting

CVE-2024-9416 Medium 2.10.2
CVE-2024-9416 Modula Image Gallery – Photo Grid & Video Gallery Stored Cross-Site Scripting

Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Modula Image Gallery – Photo Grid & Video Gallery so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
15 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 5 high severity findings.
Recent CVEs
CVE-2026-39481, CVE-2026-1254 and CVE-2026-23976
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Modula Image Gallery – Photo Grid & Video Gallery

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-39481
CVE-2026-39481: Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 - Authenticated (Author+) PHP Object Injection

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.14.18 via deserialization of untrusted input. This makes it possible for authenticated attackers, with author-level access and abov...

Published
Apr 20, 2026
Patched Release
2.14.19
Affected Versions
Versions up to 2.14.18
Next Step
Update to 2.14.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1254
CVE-2026-1254: Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them...

Published
Feb 13, 2026
Patched Release
2.13.7
Affected Versions
Versions up to 2.13.6
Next Step
Update to 2.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-23976
CVE-2026-23976: Modula Image Gallery <= 2.13.4 - Authenticated (Author+) Stored Cross-Site Scripting

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,...

Published
Feb 04, 2026
Patched Release
2.13.5
Affected Versions
Versions up to 2.13.4
Next Step
Update to 2.13.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14003
CVE-2025-14003: Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This makes it possible for aut...

Published
Dec 15, 2025
Patched Release
2.13.4
Affected Versions
Versions up to 2.13.3
Next Step
Update to 2.13.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13891
CVE-2025-13891: Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endp...

Published
Dec 11, 2025
Patched Release
2.13.4
Affected Versions
Versions up to 2.13.3
Next Step
Update to 2.13.4 or newer if supported.
Plugin High Patched: Yes CVE-2025-13646
CVE-2025-13646: Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upl...

Published
Dec 02, 2025
Patched Release
2.13.3
Affected Versions
2.13.1 through 2.13.2
Next Step
Update to 2.13.3 or newer if supported.
Plugin High Patched: Yes CVE-2025-13645
CVE-2025-13645: Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above,...

Published
Dec 02, 2025
Patched Release
2.13.3
Affected Versions
2.13.1 through 2.13.2
Next Step
Update to 2.13.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24939
CVE-2026-24939: Modula Image Gallery <= 2.13.6 - Missing Authorization

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.13.6. This makes it possible for authenticated attackers, with Subscriber-level...

Published
Nov 22, 2025
Patched Release
2.13.7
Affected Versions
Versions up to 2.13.6
Next Step
Update to 2.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12494
CVE-2025-12494: Image Gallery – Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers...

Published
Nov 14, 2025
Patched Release
2.12.29
Affected Versions
Versions up to 2.12.28
Next Step
Update to 2.12.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9416
CVE-2024-9416: Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions

Published
Apr 02, 2025
Patched Release
2.10.2
Affected Versions
Versions up to 2.10.1
Next Step
Update to 2.10.2 or newer if supported.
Plugin High Patched: Yes CVE-2024-12853
CVE-2024-12853: Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access an...

Published
Jan 07, 2025
Patched Release
2.11.11
Affected Versions
Versions up to 2.11.10
Next Step
Update to 2.11.11 or newer if supported.
Plugin Low Patched: Yes
Modula <= 2.7.4 - Incomplete Authorization via 'save_image' and 'save_images'

The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check on the 'save_image' and 'save_images' functions in versions up to, and including, 2.7.4. This makes it possible for authenticated attackers with the 'edit_othe...

Published
Sep 10, 2023
Patched Release
2.7.5
Affected Versions
Versions before 2.7.5
Next Step
Update to 2.7.5 or newer if supported.