Unauthorized Disclosure Vulnerability in Modula Image Gallery Plugin for WordPress
CVE-2026-89406
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-89406?
The Modula Image Gallery plugin for WordPress has a vulnerability that allows unauthorized access to private gallery content. This is due to a flaw in the Modula_Meta::add_metas() function, which does not properly check a gallery's visibility or the requester's permissions. As a result, unauthenticated users can exploit this weakness to access sensitive information about private media, including images and their metadata, via leaked Open Graph/Twitter meta tags. This allows for the potential unauthorized download of private content, posing significant privacy risks for users.
Affected Version(s)
Modula Image Gallery β Photo Grid & Video Gallery 0 <= 3.0.1