Arbitrary File Deletion in Modula Image Gallery Plugin for WordPress
CVE-2026-92713
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-92713?
The Modula Image Gallery plugin for WordPress has a vulnerability that allows authenticated users with author-level access and above to delete any file on the server. This occurs due to insufficient validation in the upload_image function, enabling attackers to bypass intended restrictions. The design flaw allows files stored within the wp-content/uploads directory to be manipulated despite their ownership, making it a significant risk for sites using this plugin.
Affected Version(s)
Modula Image Gallery β Photo Grid & Video Gallery 0 <= 3.0.2