CVE-2022-41135 MEDIUM

CVE-2022-41135: WordPress Modula plugin <= 2.6.9 - Unauth. Plugin Settings Change vulnerability

Vendor Wpchill
Product Modula Image Gallery (WordPress plugin)
Weakness CWE-284
Published November 18, 2022
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Modula Image Gallery WordPress plugin through version 2.6.9 contains an access control flaw that allows unauthenticated attackers to modify site data over the network. The vulnerability does not require user interaction or special conditions. Site administrators should update the plugin immediately to prevent unauthorized changes to gallery content and settings.

What an attacker can do

03Attacker Capabilities

Modify gallery data and site settings without authentication.

Potential impact on your site

04Site Impact

Attackers can alter or delete image galleries and related content without your permission.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE