Description
Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Described as an unauthenticated cross‑site scripting (CWE‑79) flaw in WordPress Modula‑PRO plugin versions up to 2.10.8, allowing an attacker to inject malicious scripts that will execute in the browsers of any site visitor.

Affected Systems

Versions of the Modula‑PRO plugin from Chill Media Labs S.R.L. up to and including 2.10.8 are affected. WordPress sites that have not upgraded to at least versions 2.10.9 remain vulnerable.

Risk and Exploitability

CVSS v3.1 score of 7.1 indicates high severity. EPSS score of less than 1% shows a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The CVE explicitly states the flaw is unauthenticated, meaning no login is required for exploitation. While the description does not detail the attack vector, it is inferred that an attacker could target unauthenticated users through publicly accessible plugin interfaces to inject scripts. The high severity rating signals that impact on user confidentiality and integrity could arise if the injected script is used maliciously.

Generated by OpenCVE AI on July 21, 2026 at 11:47 UTC.

Remediation

Vendor Solution

Update the WordPress Modula - PRO Plugin to the latest available version (at least 2.10.9).


OpenCVE Recommended Actions

  • Update the Modula‑PRO plugin to version 2.10.9 or later.
  • If an immediate update is not possible, disable or uninstall the Modula‑PRO plugin to eliminate the vulnerability.
  • Deploy a Content Security Policy that blocks inline scripts to reduce the impact of potential XSS.

Generated by OpenCVE AI on July 21, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Chill Media Labs S.r.l.
Chill Media Labs S.r.l. modula - Pro
Wordpress
Wordpress wordpress
Vendors & Products Chill Media Labs S.r.l.
Chill Media Labs S.r.l. modula - Pro
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.
Title WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Chill Media Labs S.r.l. Modula - Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:10:28.862Z

Reserved: 2026-06-24T12:46:44.605Z

Link: CVE-2026-57426

cve-icon Vulnrichment

Updated: 2026-07-02T12:10:25.361Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')