Skip to content
Noroxi

Gallery by FooGallery

foogallery · plugin

Known security vulnerabilities for Gallery by FooGallery. Find out in seconds which version runs on your site with WP Lens.

16 known vulnerabilities

1 with public exploit code · latest Sep 5, 2026

Vulnerabilities

  • CVE-2023-44233

    WordPress FooGallery Plugin <= 2.2.44 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2026-85414

    Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute

    Medium 6.4
  • CVE-2026-9134

    Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cus

    Medium 6.4
  • CVE-2023-44244

    WordPress FooGallery Plugin <= 2.2.44 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2023-29439

    WordPress FooGallery Plugin <= 2.2.35 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2026-25362

    WordPress FooGallery plugin <= 3.1.11 - Cross Site Scripting (XSS) vulnerability

    Medium 5.9
  • CVE-2025-6068

    FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptin

    Medium 5.4
  • CVE-2024-12119

    FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Tit

    Medium 5.4
  • CVE-2024-2122

    FooGallery <= 2.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL

    Medium 5.4
  • CVE-2024-2081

    FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2024-2471

    FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields

    Medium 5.4
  • CVE-2023-6747

    FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2025-22624

    FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS)

    Medium 5.1
  • CVE-2026-25363

    WordPress FooGallery plugin <= 3.1.11 - Broken Access Control vulnerability

    Medium 4.3
  • CVE-2025-15524

    Gallery by FooGallery <= 3.1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure

    Medium 4.3
  • CVE-2024-12114

    FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbit

    Medium 4.3

← Back to directory