Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter
medium
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTM...
- CVSS:
- 6.4
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.32
- Disclosed:
- Jun 12, 2026
CVE-2026-9134 on NVD →
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 2.4.27
- Fixed in:
- 2.4.29
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Gallery by FooGallery [foogallery] <= 3.1.11 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11.
- Affected:
- up to 3.1.11
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25362 on NVD →
Gallery by FooGallery [foogallery] <= 3.1.11 (unfixed)
unknown
[en] Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11.
- Affected:
- up to 3.1.11
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25363 on NVD →
FooGallery <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.13
- Disclosed:
- Feb 15, 2026
CVE-2026-25362 on NVD →
FooGallery <= 3.1.11 - Missing Authorization
medium
The FooGallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.13
- Disclosed:
- Feb 15, 2026
CVE-2026-25363 on NVD →
Gallery by FooGallery [foogallery] < 3.1.10
unknown
[en] The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve...
- Affected:
- up to 3.1.10
- Fixed in:
- 3.1.10
- Disclosed:
- Feb 11, 2026
CVE-2025-15524 on NVD →
Gallery by FooGallery <= 3.1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure
medium
The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve metad...
- CVSS:
- 4.3
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.10
- Disclosed:
- Feb 10, 2026
CVE-2025-15524 on NVD →
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 2.4.31
- Fixed in:
- 2.4.32
- Disclosed:
- Jul 10, 2025
CVE-2025-6068 on NVD →
Gallery by FooGallery [foogallery] < 2.4.30
unknown
[en] The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes i...
- Affected:
- up to 2.4.30
- Fixed in:
- 2.4.30
- Disclosed:
- Mar 8, 2025
CVE-2024-12119 on NVD →
Gallery by FooGallery [foogallery] < 2.4.30
unknown
[en] The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id)...
- Affected:
- up to 2.4.30
- Fixed in:
- 2.4.30
- Disclosed:
- Mar 8, 2025
CVE-2024-12114 on NVD →
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size
medium
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes it pos...
- CVSS:
- 6.4
- Affected:
- up to 2.4.29
- Fixed in:
- 2.4.30
- Disclosed:
- Mar 7, 2025
CVE-2024-12119 on NVD →
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates
medium
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). Thi...
- CVSS:
- 4.3
- Affected:
- up to 2.4.29
- Fixed in:
- 2.4.30
- Disclosed:
- Mar 7, 2025
CVE-2024-12114 on NVD →
FooGallery <= 2.4.29 - Reflected Cross-Site Scripting
medium
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'foogallery_id' parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 2.4.29
- Fixed in:
- 2.4.30
- Disclosed:
- Feb 27, 2025
CVE-2025-22624 on NVD →
Gallery by FooGallery [foogallery] < 2.4.30
unknown
[en] FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/extensions/albums/admin/class-meta boxes.php.
- Affected:
- up to 2.4.30
- Fixed in:
- 2.4.30
- Disclosed:
- Feb 27, 2025
CVE-2025-22624 on NVD →
Gallery by FooGallery [foogallery] < 2.1.34
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Gallery by FooGallery [foogallery] < 2.4.16
unknown
[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...
- Affected:
- up to 2.4.16
- Fixed in:
- 2.4.16
- Disclosed:
- Jun 14, 2024
CVE-2024-2122 on NVD →
FooGallery <= 2.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.16
- Disclosed:
- Jun 13, 2024
CVE-2024-2122 on NVD →
Gallery by FooGallery [foogallery] < 2.4.15
unknown
[en] The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be use...
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Jun 13, 2024
CVE-2024-2762 on NVD →
FooGallery (Free and Premium) < 2.4.15 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author acc...
- CVSS:
- 6.4
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- May 23, 2024
CVE-2024-2762 on NVD →
Gallery by FooGallery [foogallery] < 2.4.15
unknown
[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Apr 9, 2024
CVE-2024-2081 on NVD →
Gallery by FooGallery [foogallery] < 2.4.15
unknown
[en] The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possib...
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Apr 6, 2024
CVE-2024-2471 on NVD →
FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.4
- Affected:
- up to 2.4.14
- Fixed in:
- 2.4.15
- Disclosed:
- Apr 5, 2024
CVE-2024-2081 on NVD →
FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields
medium
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.4
- Affected:
- up to 2.4.14
- Fixed in:
- 2.4.15
- Disclosed:
- Apr 5, 2024
CVE-2024-2471 on NVD →
Gallery by FooGallery [foogallery] < 2.4.9
unknown
[en] The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Feb 20, 2024
CVE-2024-0604 on NVD →
Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...
- CVSS:
- 4.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.9
- Disclosed:
- Feb 14, 2024
CVE-2024-0604 on NVD →
FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Jan 2, 2024
CVE-2023-6747 on NVD →
Gallery by FooGallery [foogallery] < 2.3.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Oct 6, 2023
CVE-2023-44233 on NVD →
Gallery by FooGallery [foogallery] < 2.3.2
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Oct 2, 2023
CVE-2023-44244 on NVD →
FooGallery <= 2.2.44 - Reflected Cross-Site Scripting
high
The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' parameters in versions up to, and including, 2.2.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 7.2
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Sep 29, 2023
CVE-2023-44244 on NVD →
FooGallery <= 2.2.44 - Cross-Site Request Forgery
medium
The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44. This is due to missing nonce validation on the handle_extension_action() function. This makes it possible for unauthenticated attackers to activate, download, and deactivate extensions via a forged...
- CVSS:
- 4.3
- Affected:
- up to 2.2.44
- Fixed in:
- 2.3.2
- Disclosed:
- Sep 29, 2023
CVE-2023-44233 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.3.29 – 2.2.41
- Fixed in:
- 2.2.44
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Gallery by FooGallery [foogallery] < 2.2.41
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.
- Affected:
- up to 2.2.41
- Fixed in:
- 2.2.41
- Disclosed:
- May 16, 2023
CVE-2023-29439 on NVD →
FooGallery <= 2.2.35 - Reflected Cross-Site Scripting
medium
The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...
- CVSS:
- 6.1
- Affected:
- up to 2.2.35
- Fixed in:
- 2.2.41
- Disclosed:
- Apr 13, 2023
CVE-2023-29439 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Gallery by FooGallery [foogallery] < 2.1.34
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34
- Disclosed:
- Mar 4, 2022
Gallery by FooGallery [foogallery] < 2.1.34
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress FooGallery plugin (versions <= 2.1.33).
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34
- Disclosed:
- Feb 28, 2022
Gallery by FooGallery [foogallery] < 2.1.34
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress FooGallery plugin (versions <= 2.1.33).
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34
- Disclosed:
- Feb 28, 2022
Gallery by FooGallery [foogallery] < 2.0.35
unknown
[en] In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.
- Affected:
- up to 2.0.35
- Fixed in:
- 2.0.35
- Disclosed:
- Jun 14, 2021
CVE-2021-24357 on NVD →
FooGallery <= 2.0.34 - Stored Cross-Site Scripting
medium
In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.
- CVSS:
- 6.4
- Affected:
- up to 2.0.35
- Fixed in:
- 2.0.35
- Disclosed:
- May 31, 2021
CVE-2021-24357 on NVD →
Gallery by FooGallery [foogallery] < 1.9.25
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by VishnuPriya Ilango (Fortinet FortiGuard Labs) in WordPress FooGallery plugin (versions <= 1.9.24).
- Affected:
- up to 1.9.25
- Fixed in:
- 1.9.25
- Disclosed:
- Aug 27, 2020
FooGallery <= 1.8.12 - Cross-Site Scripting
medium
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. Please note this requires administrative privileges to exploit.
- CVSS:
- 4.8
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.18
- Disclosed:
- Jun 1, 2020
CVE-2019-20182 on NVD →
FooGallery <= 1.9.24 - Authenticated Cross-Site Scripting
high
The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in the gallery media upload editor in versions up to, and including, 1.9.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitr...
- CVSS:
- 8.3
- Affected:
- up to 1.9.25
- Fixed in:
- 1.9.25
- Disclosed:
- May 4, 2020
Gallery by FooGallery [foogallery] < 1.9.25
unknown
The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in the gallery media upload editor in versions up to, and including, 1.9.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitr...
- Affected:
- up to 1.9.25
- Fixed in:
- 1.9.25
- Disclosed:
- May 4, 2020
Gallery by FooGallery [foogallery] < 1.8.18
unknown
[en] The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
- Affected:
- up to 1.8.18
- Fixed in:
- 1.8.18
- Disclosed:
- Jan 9, 2020
CVE-2019-20182 on NVD →
Gallery by FooGallery [foogallery] < 1.6.17
unknown
Authenticated Option Update vulnerability (Fremius Library security issue) found in WordPress FooGallery plugin (versions <= 1.6.15).
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.17
- Disclosed:
- Mar 2, 2019
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
high
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- CVSS:
- 8.8
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.17
- Disclosed:
- Feb 25, 2019
Gallery by FooGallery [foogallery] < 1.6.17
unknown
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.17
- Disclosed:
- Feb 25, 2019
Gallery by FooGallery [foogallery] < 2.2.44
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.2.44
- Fixed in:
- 2.2.44
CVE-2023-33999 on NVD →
Gallery by FooGallery [foogallery] < 1.9.25
unknown
The FooGallery WordPress plugin was found to be vulnerable to Authenticated Cross-Site Scripting (XSS).
"The vulnerability is caused by improper sanitization of user input in the image title or caption parameters in the gallery media upload editor. Thereby it can lead to an XSS in the default lightbox feature....
- Affected:
- up to 1.9.25
- Fixed in:
- 1.9.25
Gallery by FooGallery [foogallery] < 2.4.32
unknown
- Affected:
- up to 2.4.32
- Fixed in:
- 2.4.32
CVE-2025-6068 on NVD →
Gallery by FooGallery [foogallery] < 1.6.17
unknown
The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.17
Gallery by FooGallery [foogallery] < 2.1.34
unknown
The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...
- Affected:
- up to 2.1.34
- Fixed in:
- 2.1.34