Showing 1 vulnerability on this page for Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Signals CISA KEV Ransomware Nuclei
fooplugins vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, onerror) while permitting others such as 'onmouseenter', combined with the failure to escape

CWE-79Jun 13, 2026
CVSS6.4v3.1EPSS0.301%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX