Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
high
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive...
- CVSS:
- 7.7
- Affected:
- up to 2.4.26
- Fixed in:
- 2.4.27
- Disclosed:
- Dec 9, 2024
CVE-2023-6947 on NVD →
FooGallery (Free and Premium) < 2.4.15 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author acc...
- CVSS:
- 6.4
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- May 23, 2024
CVE-2024-2762 on NVD →
FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 2.3.3
- Fixed in:
- 2.4.6
- Disclosed:
- Jan 2, 2024
CVE-2023-6747 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database