CVE-2024-12853

Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 6,411 live websites that are affected by CVE-2024-12853.

Test my site




Affected Software

Product  Modula Best Grid Gallery
Category Wordpress Plugins
Vulnerable Domains6,411 live websites (62.22% of Modula Best Grid Gallery install base)
Vulnerable Versions
  • from 0 through 2.11.10
Vulnerable Versions Count101 versions ( 93.52% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jan 8, 2025
  • Updated - Jan 8, 2025

Credits

  • SavPhill (finder)

CVE-2024-12853 usage by Country

United States1,723 websites



Germany945 websites
France499 websites
Poland335 websites
GB287 websites
Spain217 websites
Italy204 websites
Netherlands202 websites
Switzerland130 websites
Russia113 websites

CVE-2024-12853 usage by TLD

.com2,485 websites
.de519 websites
.pl274 websites
.co.uk231 websites
.org187 websites
.nl187 websites
.fr178 websites
.it156 websites
.es123 websites
.net112 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-12853

Top websites that are affected by CVE-2024-12853. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.***.uk GB***,***
*******************.com Singapore***,***
************.de Germany***,***
******.com United States***,***
*****.**.tz GB***,***
**********.com United States***,***
******.pl Poland***,***
*****************.com United States***,***
**********.com Germany***,***
***********************.**.uk GB***,***
See full domain list

FAQ

CVE-2024-12853 is Unrestricted Upload of File with Dangerous Type in Modula Best Grid Gallery
A total of 6,411 websites have been identified as vulnerable to CVE-2024-12853, discovered through global website indexing conducted by WebTechSurvey.
Modula Best Grid Gallery is susceptible to CVE-2024-12853 vulnerability.
Modula Best Grid Gallery versions before, and including, 2.11.10 are vulnerable to CVE-2024-12853.