Junglewise Threat Intelligence

CVE-2026-42688: WP Chill Modula Image Gallery Cross Site Scripting

CVE-2026-42688 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: WP Chill Modula Image Gallery. Vendors: WP Chill.

Executive brief

Modula Image Gallery is a popular WordPress plugin used to create and manage photo galleries. A security flaw allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected content, the attacker could potentially hijack sessions, redirect users to malicious sites, or deface the website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Modula Image Gallery plugin for WordPress (versions up to and including 2.14.23) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Subscriber' privileges to inject arbitrary web scripts. Successful exploitation requires a victim (such as an administrator) to interact with the malicious payload, which then executes in the context of the victim's browser. This can lead to session hijacking, unauthorized data access, or site redirection. The issue is resolved in version 2.14.24.

Affected products

  • WP Chill Modula Image Gallery <= 2.14.23

Timeline

  • 2026-04-26: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-05-26: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published in NVD
  • 2026-05-26: patched: Version 2.14.24 released to address the issue

References

Related threats