Extension WordPress

Vulnérabilités Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Cette page rassemble les failles publiées pour Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
24Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

24 fiches

CVE-2026-9134 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which…

Versions affectées

*-3.1.31

Correctif

3.1.32

Publication

12/06/2026

CVE-2024-13362 Moyenne · 6,1
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-2.4.27

Correctif

2.4.29

Publication

30/04/2026

CVE-2026-25362 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 3.1.11 – Authenticated (Author+) Stored Cross-Site Scripting

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…

Versions affectées

*-3.1.11

Correctif

3.1.13

Publication

15/02/2026

CVE-2026-25363 Moyenne · 4,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 3.1.11 – Missing Authorization

The FooGallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-3.1.11

Correctif

3.1.13

Publication

15/02/2026

CVE-2025-15524 Moyenne · 4,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Gallery by FooGallery <= 3.1.9 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure

The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated…

Versions affectées

*-3.1.9

Correctif

3.1.10

Publication

10/02/2026

CVE-2025-6068 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to…

Versions affectées

*-2.4.31

Correctif

2.4.32

Publication

10/07/2025

CVE-2024-12114 Moyenne · 4,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 – Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing…

Versions affectées

*-2.4.29

Correctif

2.4.30

Publication

07/03/2025

CVE-2024-12119 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 – Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization…

Versions affectées

*-2.4.29

Correctif

2.4.30

Publication

07/03/2025

CVE-2025-22624 Moyenne · 6,1
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.4.29 – Reflected Cross-Site Scripting

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'foogallery_id' parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization…

Versions affectées

*-2.4.29

Correctif

2.4.30

Publication

27/02/2025

CVE-2024-2122 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.4.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.4.15

Correctif

2.4.16

Publication

13/06/2024

CVE-2024-2762 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery (Free and Premium) < 2.4.15 – Authenticated (Author+) Stored Cross-Site Scripting

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Class parameter in all versions up to 2.4.15 (exclusive) due to insufficient input sanitization and output escaping. This…

Versions affectées

[*, 2.4.15)

Correctif

2.4.15

Publication

23/05/2024

CVE-2024-2081 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.4.14 – Authenticated (Author+) Stored Cross-Site Scripting

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.4.14

Correctif

2.4.15

Publication

05/04/2024

CVE-2024-2471 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.4.14 – Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient…

Versions affectées

*-2.4.14

Correctif

2.4.15

Publication

05/04/2024

CVE-2024-0604 Moyenne · 4,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.4.7

Correctif

2.4.9

Publication

14/02/2024

CVE-2023-6747 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery Premium <= 2.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.4.8

Correctif

2.4.9

Publication

02/01/2024

CVE-2023-44233 Moyenne · 4,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.2.44 – Cross-Site Request Forgery

The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44. This is due to missing nonce validation on the handle_extension_action() function. This makes it possible for unauthenticated attackers to activate,…

Versions affectées

*-2.2.44

Correctif

2.3.2

Publication

29/09/2023

CVE-2023-44244 Élevée · 7,2
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.2.44 – Reflected Cross-Site Scripting

The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' parameters in versions up to, and including, 2.2.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

[*, 2.3.2)

Correctif

2.3.2

Publication

29/09/2023

CVE-2023-33999 Moyenne · 6,1
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

1.3.29-2.2.41

Correctif

2.2.44

Publication

18/07/2023

CVE-2023-29439 Moyenne · 6,1
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.2.35 – Reflected Cross-Site Scripting

The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-2.2.35

Correctif

2.2.41

Publication

13/04/2023

CVE-2022-4974 Moyenne · 6,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 2.1.34)

Correctif

2.1.34

Publication

04/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités