The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). This makes it possible for authenticated attackers, with granted access and above, to update arbitrary post and page content. This requires the Gallery Creator Role setting to be a value lower than 'Editor' for there to be any real impact.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Fooplugins
Fooplugins foogallery
CPEs cpe:2.3:a:fooplugins:foogallery:*:*:*:*:-:wordpress:*:*
Vendors & Products Fooplugins
Fooplugins foogallery

Mon, 10 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Mar 2025 05:45:00 +0000

Type Values Removed Values Added
Description The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). This makes it possible for authenticated attackers, with granted access and above, to update arbitrary post and page content. This requires the Gallery Creator Role setting to be a value lower than 'Editor' for there to be any real impact.
Title FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-10T16:11:56.871Z

Reserved: 2024-12-03T20:45:57.298Z

Link: CVE-2024-12114

cve-icon Vulnrichment

Updated: 2025-03-10T16:11:52.834Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-08T06:15:35.103

Modified: 2025-03-12T16:24:29.630

Link: CVE-2024-12114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.