9 results (0.007 seconds)

CVSS: 7.7EPSS: 0%CPEs: 1EXPL: 0

09 Dec 2024 — The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure. • https://github.com/fooplugins/foogallery/pull/263/commits/9989f6f4f4d478ec04cb634d09b18c87a5b31c4d • CWE-25: Path Traversal: '/../filedir' •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 1

28 May 2024 — The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). El complemento Lightbox & Modal Popup WordPress Plugin de WordPress anterior a 2.7.28, el complemento foobox-image-lightbox-premium... • https://wpscan.com/vulnerability/996d3247-ebdd-49d1-a1a3-ceedcf9f2f95 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 2EXPL: 1

23 May 2024 — The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin El complemento FooGallery de WordPress anterior a 2.4.15, el complemento foogallery-premium de WordPress anterior a 2.4.15 no valida ni escapa algunas de... • https://wpscan.com/vulnerability/92e0f5ca-0184-4e9c-b01a-7656e05dce69 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

02 Jan 2024 — The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Best WordPress Gallery Plugin – FooGallery plugin for WordPress es vulnerable a Cross-Site Scripting almacenado a tra... • https://fooplugins.com/foogallery-wordpress-gallery-plugin/pricing • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

29 Sep 2023 — Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento FooPlugins FooGallery en versiones <= 2.2.44. The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' parameters in versions up to, and including, 2.2.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthen... • https://patchstack.com/database/vulnerability/foogallery/wordpress-foogallery-plugin-2-2-44-reflected-cross-site-scripting-xss-vulnerability-2?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

29 Sep 2023 — Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en FooPlugins Best WordPress Gallery Plugin – complemento FooGallery en versiones <= 2.2.44. The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44. This is due to missing nonce validation on the handle_extension_action() function. This makes it possible for ... • https://patchstack.com/database/vulnerability/foogallery/wordpress-foogallery-plugin-2-2-44-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 2

13 Apr 2023 — Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Unauth. • https://github.com/LOURC0D3/CVE-2023-29439 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 1

31 May 2021 — In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue. En el plugin de WordPress Best Image Gallery & Responsive Photo Gallery versiones anteriores a 2.0.35, el campo CSS personalizado de cada galería no es saneado o comprobado apropiadamente antes de aparecer en la página e... • https://wpscan.com/vulnerability/950f46ae-4476-4969-863a-0e55752953b3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

09 Jan 2020 — The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. El plugin FooGallery versión 1.8.12 para WordPress, permite un ataque de tipo XSS por medio del parámetro post_title. The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. Please note this requires administrative privileges to exploit. • https://medium.com/%40Pablo0xSantiago/cve-2019-20182-foogallery-image-gallery-wordpress-plugin-1-8-12-stored-cross-site-scripting-d5864f1259f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •