Impact
The Modula Image Gallery plugin contains a missing authorization flaw that allows authenticated WordPress users with author-level access or higher to delete arbitrary files on the server. The flaw stems from insufficient validation of the 'file' parameter in the upload_image function, enabling a malicious user to specify any path within the uploads directory or beyond, thereby deleting vital files. This vulnerability is identified as CWE-862 and can lead to data loss, site compromise, or denial of service.
Affected Systems
The vulnerability affects the Modula Image Gallery – Photo Grid & Video Gallery plugin produced by wpchill. All releases up to and including version 3.0.2 are impacted. WordPress sites using this plugin are at risk if they have author or higher privileges.
Risk and Exploitability
The CVSS score of 8.1 classifies this defect as high severity, and the lack of an EPSS score indicates insufficient public data, though the inherent exploitability remains significant. The attack requires an authenticated attacker with author-level access, which is a common privilege tier on many sites, making the vulnerability likely to be abused. The vulnerability is not currently listed in the CISA KEV catalog, but the impact and accessible privilege level suggest a considerable risk if not patched.
OpenCVE Enrichment