CVE-2026-105876: WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Modula Image Galleryto a version that resolves this vulnerability.Fixed in 3.0.12
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable with low attack complexity and requires no privileges or user interaction. An unauthenticated attacker may be able to retrieve embedded sensitive data.
Which installations are affected?
WP Chill Modula Image Gallery versions through 3.0.11 are affected. The available data does not identify a fixed version or any configuration prerequisite.
What is the expected impact?
The reported impact is limited to confidentiality: sensitive embedded data may be exposed. No integrity or availability impact is indicated.