Executive brief
WP Chill Modula Image Gallery, a popular WordPress plugin for creating photo and video galleries, contains a security vulnerability that allows for stored cross-site scripting. An attacker with contributor-level access can inject malicious scripts into the website, which could lead to unauthorized redirects, the display of fraudulent advertisements, or the theft of session information from other users. This could compromise the integrity of the website and the security of its visitors.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the WP Chill Modula Image Gallery plugin for WordPress (versions 2.14.25 through 2.14.30). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker with 'Contributor' or higher privileges to inject malicious scripts into gallery components. These scripts are then executed in the browser of any user (including administrators) who views the affected page. Exploitation requires minimal user interaction, such as a victim visiting the page where the malicious payload is stored. The issue is resolved in version 2.14.31.
Affected products
- WP Chill Modula Image Gallery 2.14.25 through 2.14.30
Timeline
- 2026-07-17: other: Reported by Abdullah Kareem
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date
- 2026-07-23: patched: Patch available in version 2.14.31