CVE-2026-1254 | Modula Image Gallery Plugin up to 2.13.6 on WordPress REST API modulaImages authorization
A vulnerability was found in Modula Image Gallery Plugin up to 2.13.6 on WordPress. It has been declared as problematic. Affected is an unknown function of the component REST API. The manipulation of the argument modulaImages results in missing authorization.
This vulnerability is known as CVE-2026-1254. It is possible to launch the attack remotely. No exploit is available.