Junglewise Threat Intelligence

CVE-2026-39481: WP Chill Modula Image Gallery PHP object injection

CVE-2026-39481 · Severity: high · CVSS 7.2 · Published 2026-06-15

Technologies: WP Chill Modula Image Gallery. Vendors: WP Chill.

Executive brief

Modula Image Gallery, a popular WordPress plugin used for creating photo and video galleries, contains a security flaw that allows users with 'Author' level permissions to inject malicious code. If exploited, an attacker could potentially take full control of the website, access sensitive data, or disrupt site operations. This vulnerability is particularly dangerous if a site allows multiple contributors or has compromised accounts with elevated privileges.

Technical details

The Modula Image Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to 2.14.18 due to the deserialization of untrusted data (CWE-502). This vulnerability allows an authenticated attacker with Author-level permissions to inject a PHP object. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, arbitrary file deletion, or sensitive data exposure. The issue is resolved in version 2.14.19.

Affected products

  • WP Chill Modula Image Gallery <= 2.14.18

Timeline

  • 2026-02-25: other: Reported by researcher daroo
  • 2026-04-20: patched: Patch released in version 2.14.19
  • 2026-06-15: disclosed: NVD publication date

References

Related threats