WP Vulnerability WatchVulnerability data as of September 26, 2026

Vulnerability alerts / September 25, 2026

Vulnerability in Modula Image Gallery – Photo Grid & Video Gallery — CVE-2026-92713

HighSeverity
CVSS 8.1
0.3%Estimated exploit probability
EPSS
100,000+ sitesInstalls
3.0.3Fixed in

What to do now

Update Modula Image Gallery – Photo Grid & Video Gallery to 3.0.3 or later.

Affected versions

  • Everything up to and including 3.0.2

Affected: Modula Image Gallery – Photo Grid & Video Gallery (plugin, modula-best-grid-gallery)

Check: The plugin on wordpress.org / Our record for Modula Image Gallery – Photo Grid & Video Gallery

What the vulnerability is

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server. The path restriction to wp-content/uploads is not an effective ownership boundary, as all user attachment files reside within that tree, and Authors trivially satisfy the edit_post check on their own galleries.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts