plugin

Foogallery Premium Vulnerabilities

3 known security issues reported for the Foogallery Premium WordPress plugin. Most recent disclosed Dec 9, 2024.

1 high 2 medium

Running Foogallery Premium on your site? Check whether your installed version is affected.

Scan your site free

Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

high

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive...

CVSS:
7.7
Affected:
up to 2.4.26
Fixed in:
2.4.27
Disclosed:
Dec 9, 2024

CVE-2023-6947 on NVD →

FooGallery (Free and Premium) < 2.4.15 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author acc...

CVSS:
6.4
Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
May 23, 2024

CVE-2024-2762 on NVD →

FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 2.3.3
Fixed in:
2.4.6
Disclosed:
Jan 2, 2024

CVE-2023-6747 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database