PT-2020-20422 · WordPress · Modula Image Gallery

Published

2020-02-20

·

Updated

2025-12-15

·

CVE-2020-9003

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Modula Image Gallery plugin versions prior to 2.2.5
Description A stored XSS issue exists, allowing an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users. This enables the execution of malicious scripts within the context of the affected application.
Recommendations For versions prior to 2.2.5, update to version 2.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for low-privileged users until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-9003

Affected Products

Modula Image Gallery