CVE-2025-13646: Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajaxunzipfile' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condition on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13646?
CVE-2025-13646 has a high severity due to the risk of arbitrary file uploads, which can lead to remote code execution.
How do I fix CVE-2025-13646?
To fix CVE-2025-13646, update the Modula Image Gallery plugin to a version later than 2.13.2 where the vulnerability is patched.
Who is affected by CVE-2025-13646?
CVE-2025-13646 affects users of the Modula Image Gallery plugin for WordPress versions 2.13.1 to 2.13.2 with Author-level access or above.
What can attackers do with CVE-2025-13646?
Attackers exploiting CVE-2025-13646 can upload arbitrary files, potentially leading to malicious code execution on the server.
Is CVE-2025-13646 being actively exploited?
As of now, there are indications that CVE-2025-13646 may be subject to active exploitation, making it critical to address promptly.