Impact
A missing capability check in the add_images_to_gallery_callback function allows an authenticated WordPress user with Author level or higher to add images to any Modula gallery, regardless of ownership. The vulnerability lets the attacker insert or modify gallery content without permission, potentially damaging site aesthetics or distributing malicious media.
Affected Systems
All installations of the Modula Image Gallery – Photo Grid & Video Gallery plugin with version numbers up to and including 2.13.3 are affected. Users must verify their plugin version and upgrade if it falls within this range.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be exploited only by authenticated users with at least Author role, making it a local accounts‑based privilege issue rather than a remote code execution vector.
OpenCVE Enrichment