Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4.
Published: 2026-01-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

The Modula Image Gallery plugin for WordPress suffers from an improper neutralization of user input that leads to stored cross‑site scripting. The flaw permits an attacker to embed malicious scripts through the gallery management interface, and those scripts are subsequently rendered unescaped on gallery pages. When executed in the browser of any visitor to the affected page, the code can steal session cookies, deface the site, or inject further malicious content.

Affected Systems

Every instance of the Modula Image Gallery plugin provided by WP Chill that is version 2.13.4 or older is vulnerable. The plugin is widely distributed through the WordPress plugin repository and is used to display image galleries on sites that allow gallery creation and editing by privileged users.

Risk and Exploitability

The base CVSS score of 5.9 places the flaw in the medium severity range. EPSS indicates exploitation probability below 1 %. The vulnerability is not listed in the CISA KEV catalog. Attackers presumably need legitimate access to the gallery editing interface, such as an authenticated administrator or a user with editing rights, to inject the malicious payload. Once stored, the XSS can be activated whenever any user loads a gallery page, exposing all visitors to the associated risks.

Generated by OpenCVE AI on April 28, 2026 at 18:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Modula Image Gallery plugin to the latest available release that includes the security fix.
  • If no updated release exists, temporarily deactivate or uninstall the plugin until a patch is released.
  • Enforce least‑privilege on users who can edit galleries, sanitize all gallery content before display, and consider implementing a Content Security Policy that blocks inline script execution on gallery pages.

Generated by OpenCVE AI on April 28, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpchill
Wpchill modula Image Gallery
Vendors & Products Wordpress
Wordpress wordpress
Wpchill
Wpchill modula Image Gallery

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4.
Title WordPress Modula Image Gallery plugin <= 2.13.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
Wpchill Modula Image Gallery
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:47.335Z

Reserved: 2026-01-19T16:14:52.937Z

Link: CVE-2026-23976

cve-icon Vulnrichment

Updated: 2026-01-27T20:48:37.948Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:38.333

Modified: 2026-04-28T16:16:08.147

Link: CVE-2026-23976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:15:37Z

Weaknesses