Executive brief
Modula - PRO, a popular WordPress plugin used for creating image galleries, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site visitor or administrator interacts with a specially crafted link, the attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website redirection. This vulnerability affects all versions up to 2.10.8 and should be addressed immediately to protect site reputation and user data.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Modula - PRO plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (such as a site administrator) to perform a specific action, like clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized administrative actions, or defacement. The issue is resolved in version 2.10.9.
Affected products
- Chill Media Labs S.R.L. Modula - PRO <= 2.10.8
Timeline
- 2026-04-20: disclosed: Reported by Nguyen Ba Khanh
- 2026-07-01: advisory: Patchstack advisory published
- 2026-07-02: patched: NVD publication and confirmation of fix in 2.10.9