cleantalk
Vulnerabilities and Security Researches

Customizable WordPress Gallery Plugin – Modula Image Gallery, PSC-2026-64640

PSC, Research URL

PSC-2026-64640

Published on
Mar 30, 2026
Research Description
Gallery plugins are security-relevant because they render user-controlled presentation data (titles, captions, alt text, links) across public pages and often provide rich admin-side builders and lightbox features. If output handling, access control, or request integrity is weak, attackers can target stored XSS through captions or settings, force configuration changes via CSRF, or expose media metadata through misprotected endpoints. Modula Image Gallery – Photo Grid & Video Gallery version 2.14.22 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64640, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for media gallery and front-end rendering plugins.
Affected versions
Min 2.14.22, max 2.14.22.
Status
SAFE & CERTIFIED