The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
We have discovered 6,411 live websites that are affected by CVE-2024-12853.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 6,411 live websites (62.22% of Modula Best Grid Gallery install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 101 versions ( 93.52% of all versions) |
![]() | 1,723 websites |
![]() | 945 websites |
![]() | 499 websites |
![]() | 335 websites |
![]() | 287 websites |
![]() | 217 websites |
![]() | 204 websites |
![]() | 202 websites |
![]() | 130 websites |
![]() | 113 websites |
.com | 2,485 websites |
.de | 519 websites |
.pl | 274 websites |
.co.uk | 231 websites |
.org | 187 websites |
.nl | 187 websites |
.fr | 178 websites |
.it | 156 websites |
.es | 123 websites |
.net | 112 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*************.***.uk | ![]() | ***,*** | |
*******************.com | ![]() | ***,*** | |
************.de | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
*****.**.tz | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
******.pl | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
***********************.**.uk | ![]() | ***,*** |
FAQ