Extension WordPress
Vulnérabilités Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel
Cette page rassemble les failles publiées pour Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel
24 fiches
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which…
*-3.1.31
3.1.32
12/06/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.4.27
2.4.29
30/04/2026
FooGallery <= 3.1.11 – Authenticated (Author+) Stored Cross-Site Scripting
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-3.1.11
3.1.13
15/02/2026
FooGallery <= 3.1.11 – Missing Authorization
The FooGallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.1.11
3.1.13
15/02/2026
Gallery by FooGallery <= 3.1.9 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure
The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated…
*-3.1.9
3.1.10
10/02/2026
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to…
*-2.4.31
2.4.32
10/07/2025
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 – Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing…
*-2.4.29
2.4.30
07/03/2025
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 – Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization…
*-2.4.29
2.4.30
07/03/2025
FooGallery <= 2.4.29 – Reflected Cross-Site Scripting
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'foogallery_id' parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization…
*-2.4.29
2.4.30
27/02/2025
FooGallery <= 2.4.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This…
*-2.4.15
2.4.16
13/06/2024
FooGallery (Free and Premium) < 2.4.15 – Authenticated (Author+) Stored Cross-Site Scripting
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This…
[*, 2.4.15)
2.4.15
23/05/2024
FooGallery <= 2.4.14 – Authenticated (Author+) Stored Cross-Site Scripting
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes…
*-2.4.14
2.4.15
05/04/2024
FooGallery <= 2.4.14 – Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient…
*-2.4.14
2.4.15
05/04/2024
Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it…
*-2.4.7
2.4.9
14/02/2024
FooGallery Premium <= 2.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes…
*-2.4.8
2.4.9
02/01/2024
FooGallery <= 2.2.44 – Cross-Site Request Forgery
The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44. This is due to missing nonce validation on the handle_extension_action() function. This makes it possible for unauthenticated attackers to activate,…
*-2.2.44
2.3.2
29/09/2023
FooGallery <= 2.2.44 – Reflected Cross-Site Scripting
The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' parameters in versions up to, and including, 2.2.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 2.3.2)
2.3.2
29/09/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.3.29-2.2.41
2.2.44
18/07/2023
FooGallery <= 2.2.35 – Reflected Cross-Site Scripting
The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-2.2.35
2.2.41
13/04/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.1.34)
2.1.34
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.