← WordPress Vulnerabilities
WordPress security by component

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Jun 13, 2026; the highest CVE/CNA score is 7.7.

Plugin slug: foogallery

CVE-2026-9134: Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel: Cross-site scripting

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.1.31.

PublishedJun 13, 2026
Known safe version> 3.1.31
Safe version
Jun 13, 2026 CVE-2026-9134
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel: Cross-site scripting
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.1.31.
> 3.1.31
CVE6.4
NVDPending
Feb 19, 2026 CVE-2026-25363
FooGallery: A security weakness
FooGallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 19, 2026 CVE-2026-25362
FooGallery: Cross-site scripting
FooGallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Feb 11, 2026 CVE-2025-15524
Gallery by FooGallery: A security weakness
Gallery by FooGallery is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 11, 2025 CVE-2025-6068
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel: Cross-site scripting
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 08, 2025 CVE-2024-12119
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel: Cross-site scripting
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 08, 2025 CVE-2024-12114
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel: A security weakness
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Feb 27, 2025 CVE-2025-22624
Foogallery: A security weakness
Foogallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.1
NVDPending
Dec 10, 2024 CVE-2023-6947
Best WordPress Gallery Plugin – FooGallery: Filesystem traversal
Best WordPress Gallery Plugin – FooGallery is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.7
NVDPending
Jun 14, 2024 CVE-2024-2122
Best WordPress Gallery Plugin – FooGallery: Cross-site scripting
Best WordPress Gallery Plugin – FooGallery is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 13, 2024 CVE-2024-2762
FooGallery: Cross-site scripting
FooGallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.3
NVD5.4
Apr 09, 2024 CVE-2024-2081
Best WordPress Gallery Plugin – FooGallery: Cross-site scripting
Best WordPress Gallery Plugin – FooGallery is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 06, 2024 CVE-2024-2471
FooGallery: Cross-site scripting
FooGallery is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-0604
Best WordPress Gallery Plugin – FooGallery: Cross-site scripting
Best WordPress Gallery Plugin – FooGallery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jan 03, 2024 CVE-2023-6747
Best WordPress Gallery Plugin – FooGallery: Cross-site scripting
Best WordPress Gallery Plugin – FooGallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 06, 2023 CVE-2023-44233
Foogallery: Cross-site request forgery
Foogallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Oct 02, 2023 CVE-2023-44244
Foogallery: Cross-site scripting
Foogallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 16, 2023 CVE-2023-29439
Foogallery: Cross-site scripting
Foogallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jun 14, 2021 CVE-2021-24357
Best Image Gallery & Responsive Photo Gallery – FooGallery: Cross-site scripting
Best Image Gallery & Responsive Photo Gallery – FooGallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jan 09, 2020 CVE-2019-20182
Foogallery: Cross-site scripting
Foogallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8