A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29834 A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 15 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpchill
Wpchill modula Image Gallery
CPEs cpe:2.3:a:machothemes:modula_image_gallery:*:*:*:*:*:wordpress:*:* cpe:2.3:a:wpchill:modula_image_gallery:*:*:*:*:*:wordpress:*:*
Vendors & Products Machothemes
Machothemes modula Image Gallery
Wpchill
Wpchill modula Image Gallery

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:19:19.661Z

Reserved: 2020-02-16T00:00:00

Link: CVE-2020-9003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-20T22:15:12.117

Modified: 2025-12-15T15:39:10.513

Link: CVE-2020-9003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses