{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/modula/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modula:image_gallery_photo_grid_video_gallery:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89406"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Modula Image Gallery – Photo Grid \u0026 Video Gallery (\u003c= 3.0.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","information-disclosure","cve-2026-89406"],"_cs_type":"advisory","_cs_vendors":["Modula"],"content_html":"\u003cp\u003eThe Modula Image Gallery - Photo Grid \u0026amp; Video Gallery plugin for WordPress is affected by an unauthenticated information disclosure vulnerability tracked as CVE-2026-89406. The issue resides in the Modula_Meta::add_metas() function, which executes on every frontend request. Due to a logical error in the parameter validation - specifically, testing a hardcoded string instead of the provided input - the plugin fails to enforce access controls when a 'modula_gallery_id' GET parameter is supplied.\u003c/p\u003e\n\u003cp\u003eThe plugin verifies that the requested post is of the type 'modula-gallery' but neglects to check the post_status or the user's authorization level. Consequently, the plugin emits Open Graph and Twitter meta tags containing sensitive gallery metadata (titles, descriptions, dimensions, and original file URLs) into the HTML response. An attacker can leverage these leaked URLs to download full-resolution private image files without authentication. This vulnerability impacts all versions up to and including 3.0.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running the Modula Image Gallery plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a GET request targeting the site, appending the 'modula_gallery_id' parameter with a guessed or enumerated gallery ID.\u003c/li\u003e\n\u003cli\u003eThe vulnerable Modula_Meta::add_metas() function hook fires during the WordPress frontend page load.\u003c/li\u003e\n\u003cli\u003eThe plugin performs a database lookup for the provided ID via get_post() without verifying the requester's identity or post status.\u003c/li\u003e\n\u003cli\u003eThe plugin fails the 'empty' input guard check due to the logic error, proceeding to process the requested gallery object.\u003c/li\u003e\n\u003cli\u003eThe server generates an HTML response containing Open Graph and Twitter meta tags that expose the private image metadata and direct source URL.\u003c/li\u003e\n\u003cli\u003eAttacker parses the HTML response to extract the original high-resolution image URL.\u003c/li\u003e\n\u003cli\u003eAttacker requests the extracted image URL to perform unauthorized exfiltration of the private image file.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized third parties to download private, restricted, or draft images hosted within the gallery. This impacts photographers and site owners who rely on WordPress privacy settings to protect sensitive or non-public visual content. In environments with large galleries, the metadata enumeration can be automated to scrape entire private collections.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Modula Image Gallery - Photo Grid \u0026amp; Video Gallery plugin to the latest version, ensuring the patch for CVE-2026-89406 is applied. Until an update is installed, implement web server-level filtering to block requests containing the 'modula_gallery_id' parameter from untrusted sources.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Modula Image Gallery to the version that remediates CVE-2026-89406.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests containing 'modula_gallery_id'.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall rules to block direct access to 'modula_gallery_id' parameters if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:57:36Z","date_published":"2026-09-25T08:57:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-modula-gallery-leak/","summary":"An unauthenticated access control vulnerability in the Modula Image Gallery WordPress plugin (\u003c= 3.0.1) allows attackers to enumerate private gallery contents and download images via insecure meta tag generation.","title":"Unauthenticated Information Disclosure in Modula Image Gallery","url":"https://feed.craftedsignal.io/briefs/2026-09-modula-gallery-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Modula","version":"https://jsonfeed.org/version/1.1"}