plugin

Foogallery Vulnerabilities

53 known security issues reported for the Foogallery WordPress plugin. Most recent disclosed Jun 12, 2026.

3 high 21 medium

Running Foogallery on your site? Check whether your installed version is affected.

Scan your site free

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter

medium

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTM...

CVSS:
6.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Jun 12, 2026

CVE-2026-9134 on NVD →

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.4.27
Fixed in:
2.4.29
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

Gallery by FooGallery [foogallery] <= 3.1.11 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11.

Affected:
up to 3.1.11
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25362 on NVD →

Gallery by FooGallery [foogallery] <= 3.1.11 (unfixed)

unknown

[en] Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11.

Affected:
up to 3.1.11
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25363 on NVD →

FooGallery <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 3.1.11
Fixed in:
3.1.13
Disclosed:
Feb 15, 2026

CVE-2026-25362 on NVD →

FooGallery <= 3.1.11 - Missing Authorization

medium

The FooGallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.1.11
Fixed in:
3.1.13
Disclosed:
Feb 15, 2026

CVE-2026-25363 on NVD →

Gallery by FooGallery [foogallery] < 3.1.10

unknown

[en] The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve...

Affected:
up to 3.1.10
Fixed in:
3.1.10
Disclosed:
Feb 11, 2026

CVE-2025-15524 on NVD →

Gallery by FooGallery <= 3.1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure

medium

The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve metad...

CVSS:
4.3
Affected:
up to 3.1.9
Fixed in:
3.1.10
Disclosed:
Feb 10, 2026

CVE-2025-15524 on NVD →

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and outpu...

CVSS:
6.4
Affected:
up to 2.4.31
Fixed in:
2.4.32
Disclosed:
Jul 10, 2025

CVE-2025-6068 on NVD →

Gallery by FooGallery [foogallery] < 2.4.30

unknown

[en] The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes i...

Affected:
up to 2.4.30
Fixed in:
2.4.30
Disclosed:
Mar 8, 2025

CVE-2024-12119 on NVD →

Gallery by FooGallery [foogallery] < 2.4.30

unknown

[en] The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id)...

Affected:
up to 2.4.30
Fixed in:
2.4.30
Disclosed:
Mar 8, 2025

CVE-2024-12114 on NVD →

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size

medium

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes it pos...

CVSS:
6.4
Affected:
up to 2.4.29
Fixed in:
2.4.30
Disclosed:
Mar 7, 2025

CVE-2024-12119 on NVD →

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates

medium

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). Thi...

CVSS:
4.3
Affected:
up to 2.4.29
Fixed in:
2.4.30
Disclosed:
Mar 7, 2025

CVE-2024-12114 on NVD →

FooGallery <= 2.4.29 - Reflected Cross-Site Scripting

medium

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'foogallery_id' parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.1
Affected:
up to 2.4.29
Fixed in:
2.4.30
Disclosed:
Feb 27, 2025

CVE-2025-22624 on NVD →

Gallery by FooGallery [foogallery] < 2.4.30

unknown

[en] FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/extensions/albums/admin/class-meta boxes.php.

Affected:
up to 2.4.30
Fixed in:
2.4.30
Disclosed:
Feb 27, 2025

CVE-2025-22624 on NVD →

Gallery by FooGallery [foogallery] < 2.1.34

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 2.1.34
Fixed in:
2.1.34
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Gallery by FooGallery [foogallery] < 2.4.16

unknown

[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...

Affected:
up to 2.4.16
Fixed in:
2.4.16
Disclosed:
Jun 14, 2024

CVE-2024-2122 on NVD →

FooGallery <= 2.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.4
Affected:
up to 2.4.15
Fixed in:
2.4.16
Disclosed:
Jun 13, 2024

CVE-2024-2122 on NVD →

Gallery by FooGallery [foogallery] < 2.4.15

unknown

[en] The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be use...

Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
Jun 13, 2024

CVE-2024-2762 on NVD →

FooGallery (Free and Premium) < 2.4.15 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author acc...

CVSS:
6.4
Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
May 23, 2024

CVE-2024-2762 on NVD →

Gallery by FooGallery [foogallery] < 2.4.15

unknown

[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
Apr 9, 2024

CVE-2024-2081 on NVD →

Gallery by FooGallery [foogallery] < 2.4.15

unknown

[en] The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possib...

Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
Apr 6, 2024

CVE-2024-2471 on NVD →

FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
6.4
Affected:
up to 2.4.14
Fixed in:
2.4.15
Disclosed:
Apr 5, 2024

CVE-2024-2081 on NVD →

FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields

medium

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.4
Affected:
up to 2.4.14
Fixed in:
2.4.15
Disclosed:
Apr 5, 2024

CVE-2024-2471 on NVD →

Gallery by FooGallery [foogallery] < 2.4.9

unknown

[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Feb 20, 2024

CVE-2024-0604 on NVD →

Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...

CVSS:
4.4
Affected:
up to 2.4.7
Fixed in:
2.4.9
Disclosed:
Feb 14, 2024

CVE-2024-0604 on NVD →

FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Jan 2, 2024

CVE-2023-6747 on NVD →

Gallery by FooGallery [foogallery] < 2.3.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Oct 6, 2023

CVE-2023-44233 on NVD →

Gallery by FooGallery [foogallery] < 2.3.2

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Oct 2, 2023

CVE-2023-44244 on NVD →

FooGallery <= 2.2.44 - Reflected Cross-Site Scripting

high

The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' parameters in versions up to, and including, 2.2.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
7.2
Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Sep 29, 2023

CVE-2023-44244 on NVD →

FooGallery <= 2.2.44 - Cross-Site Request Forgery

medium

The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44. This is due to missing nonce validation on the handle_extension_action() function. This makes it possible for unauthenticated attackers to activate, download, and deactivate extensions via a forged...

CVSS:
4.3
Affected:
up to 2.2.44
Fixed in:
2.3.2
Disclosed:
Sep 29, 2023

CVE-2023-44233 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
1.3.29 – 2.2.41
Fixed in:
2.2.44
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Gallery by FooGallery [foogallery] < 2.2.41

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.

Affected:
up to 2.2.41
Fixed in:
2.2.41
Disclosed:
May 16, 2023

CVE-2023-29439 on NVD →

FooGallery <= 2.2.35 - Reflected Cross-Site Scripting

medium

The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 2.2.35
Fixed in:
2.2.41
Disclosed:
Apr 13, 2023

CVE-2023-29439 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 2.1.34
Fixed in:
2.1.34
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Gallery by FooGallery [foogallery] < 2.1.34

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 2.1.34
Fixed in:
2.1.34
Disclosed:
Mar 4, 2022

Gallery by FooGallery [foogallery] < 2.1.34

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress FooGallery plugin (versions <= 2.1.33).

Affected:
up to 2.1.34
Fixed in:
2.1.34
Disclosed:
Feb 28, 2022

Gallery by FooGallery [foogallery] < 2.1.34

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress FooGallery plugin (versions <= 2.1.33).

Affected:
up to 2.1.34
Fixed in:
2.1.34
Disclosed:
Feb 28, 2022

Gallery by FooGallery [foogallery] < 2.0.35

unknown

[en] In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

Affected:
up to 2.0.35
Fixed in:
2.0.35
Disclosed:
Jun 14, 2021

CVE-2021-24357 on NVD →

FooGallery <= 2.0.34 - Stored Cross-Site Scripting

medium

In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

CVSS:
6.4
Affected:
up to 2.0.35
Fixed in:
2.0.35
Disclosed:
May 31, 2021

CVE-2021-24357 on NVD →

Gallery by FooGallery [foogallery] < 1.9.25

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by VishnuPriya Ilango (Fortinet FortiGuard Labs) in WordPress FooGallery plugin (versions <= 1.9.24).

Affected:
up to 1.9.25
Fixed in:
1.9.25
Disclosed:
Aug 27, 2020

FooGallery <= 1.8.12 - Cross-Site Scripting

medium

The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. Please note this requires administrative privileges to exploit.

CVSS:
4.8
Affected:
up to 1.8.12
Fixed in:
1.8.18
Disclosed:
Jun 1, 2020

CVE-2019-20182 on NVD →

FooGallery <= 1.9.24 - Authenticated Cross-Site Scripting

high

The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in the gallery media upload editor in versions up to, and including, 1.9.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitr...

CVSS:
8.3
Affected:
up to 1.9.25
Fixed in:
1.9.25
Disclosed:
May 4, 2020

Gallery by FooGallery [foogallery] < 1.9.25

unknown

The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in the gallery media upload editor in versions up to, and including, 1.9.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitr...

Affected:
up to 1.9.25
Fixed in:
1.9.25
Disclosed:
May 4, 2020

Gallery by FooGallery [foogallery] < 1.8.18

unknown

[en] The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.

Affected:
up to 1.8.18
Fixed in:
1.8.18
Disclosed:
Jan 9, 2020

CVE-2019-20182 on NVD →

Gallery by FooGallery [foogallery] < 1.6.17

unknown

Authenticated Option Update vulnerability (Fremius Library security issue) found in WordPress FooGallery plugin (versions <= 1.6.15).

Affected:
up to 1.6.17
Fixed in:
1.6.17
Disclosed:
Mar 2, 2019

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

high

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

CVSS:
8.8
Affected:
up to 1.6.17
Fixed in:
1.6.17
Disclosed:
Feb 25, 2019

Gallery by FooGallery [foogallery] < 1.6.17

unknown

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

Affected:
up to 1.6.17
Fixed in:
1.6.17
Disclosed:
Feb 25, 2019

Gallery by FooGallery [foogallery] < 2.2.44

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.2.44
Fixed in:
2.2.44

CVE-2023-33999 on NVD →

Gallery by FooGallery [foogallery] < 1.9.25

unknown

The FooGallery WordPress plugin was found to be vulnerable to Authenticated Cross-Site Scripting (XSS). &quot;The vulnerability is caused by improper sanitization of user input in the image title or caption parameters in the gallery media upload editor. Thereby it can lead to an XSS in the default lightbox feature....

Affected:
up to 1.9.25
Fixed in:
1.9.25

Gallery by FooGallery [foogallery] < 1.6.17

unknown

The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options

Affected:
up to 1.6.17
Fixed in:
1.6.17

Gallery by FooGallery [foogallery] < 2.1.34

unknown

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...

Affected:
up to 2.1.34
Fixed in:
2.1.34

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database