DIRAS TAKE
Urgent: this is a publicly reachable, unauthenticated information-disclosure bug that exposes private media; treat sites hosting Modula 3.0.1 or earlier as at immediate risk and reduce exposure until a vendor fix is available.
What is CVE-2026-89406?
Unauthenticated attackers can retrieve metadata and original URLs for private galleries and their images in Modula Image Gallery – Photo Grid & Video Gallery, CVE-2026-89406. Versions 3.0.1 and earlier on the 3.x branch are affected. The plugin emits Open Graph/Twitter meta tags for a gallery identified by a modula_gallery_id request parameter without verifying the gallery's publication status or the requester's permissions, enabling remote enumeration and direct download of private image files over the network with no user interaction or account required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of wpchill Modula Image Gallery – Photo Grid & Video Gallery are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.0.1 and earlier |
Is CVE-2026-89406 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-89406
- Remove or deactivate the Modula Image Gallery plugin until the vendor issues a fix.
- Restrict public access to galleries and media storage locations (use authentication, deny direct access via webserver rules).
- Monitor web and application logs for requests containing modula_gallery_id and for abnormal media downloads.
- Follow the vendor's guidance and apply any provided updates or patches as soon as they are released.
Frequently asked questions
Is CVE-2026-89406 being actively exploited?
There are no public reports of active exploitation of CVE-2026-89406 as of 2026-09-30.
Which Modula Image Gallery versions are affected by CVE-2026-89406?
Modula Image Gallery – Photo Grid & Video Gallery versions 3.0.1 and earlier on the 3.x branch are affected.
Is there a patch for CVE-2026-89406?
No fixed version is listed in the available vendor data; follow the vendor's guidance and remove or disable the plugin until a patch is provided.
Does CVE-2026-89406 require authentication?
No, CVE-2026-89406 can be exploited without authentication—an unauthenticated request with a gallery identifier can expose private gallery metadata and original image URLs.
References
- nvd.nist.gov/vuln/detail/CVE-2026-89406
- cve.org/CVERecord?id=CVE-2026-89406
- wordfence.com/threat-intel/vulnerabilities/id/a369dff6-feca-47cf-8511-dc75c4ffdd29?source=cve
- plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L142
- plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L50
- plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L26
- plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/social_meta.php#L8
- plugins.trac.wordpress.org/changeset?reponame=&old=3697043%40modula-best-grid-gallery&new=3697043%40modula-best-grid-gallery
- All wpchill CVEs on CVE Radar
- CVEs published in September 2026