Impact
A legacy Modula Image Gallery plugin (versions 2.14.25–2.14.30) contains improper input neutralization that permits an attacker to inject arbitrary HTML or JavaScript into pages viewed by site visitors. This is a Stored XSS vulnerability (CWE-79). The impact is that any user viewing the gallery content could have malicious scripts executed in their browser. The provided text does not specify additional outcomes beyond script execution.
Affected Systems
WordPress sites that have installed the Modula Image Gallery plugin from version 2.14.25 through 2.14.30 are vulnerable. The plugin is distributed by WP Chill under the product name Modula Image Gallery. No other products or versions are known to be affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to supply malicious input into a gallery field that is later rendered without proper escaping, so an active attacker must have some ability to contribute or modify gallery content. This requirement is inferred from the stored nature of the XSS flaw.
OpenCVE Enrichment