Impact
The Gallery : FooGallery plugin for WordPress is affected by a stored Cross‑Site Scripting flaw in the 'custom_settings' shortcode attribute. An authenticated user with contributor or higher privileges can insert arbitrary scripts that are persisted and served to other site visitors when a gallery page is rendered. The vulnerability arises from insufficient input sanitization and output escaping, as documented by the referenced source code lines. As a result, attackers can hijack the victim’s session, deface content, or perform account takeover via malicious scripts, compromising confidentiality and integrity of users who view the gallery.
Affected Systems
The vulnerability applies to all Fooplugins Gallery : FooGallery installations up to and including version 3.3.2. Administrators should check the current plugin version, and any site running 3.3.2 or earlier is at risk. The plugin is a WordPress extension maintained by Fooplugins, widely deployed across public and private WordPress sites.
Risk and Exploitability
With a CVSS base score of 6.4, the flaw is considered moderate severity. The EPSS score is not available, but the KEV list confirms it is not yet identified as a known exploited vulnerability. Attackers would require authenticated Contributor‑level access, which many sites grant to content editors, so the attack surface is relatively high for active sites. Once the malicious script is stored, any subsequent visitor to the impacted gallery page will execute the payload in their browser, enabling session hijacking, defacement, or phishing. While the flaw does not provide direct remote code execution on the server, the potential damage to user trust and site reputation is significant.
OpenCVE Enrichment