fooplugins Vulnerabilities and Affected Products
Vulnerabilities associated with Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel.
Products
Clear product- Gallery by FooGallery11 vulnerabilities
- FooGallery4 vulnerabilities
- Lightbox & Modal Popup WordPress Plugin – FooBox4 vulnerabilities
- Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar2 vulnerabilities
- Best Image Gallery & Responsive Photo Gallery – FooGallery1 vulnerability
- Best WordPress Gallery Plugin – FooGallery1 vulnerability
- FooBox Image Lightbox1 vulnerability
- foobox-image-lightbox-premium1 vulnerability
- lightbox_and_modal_popup1 vulnerability
- Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-9134MEDIUM | Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode ParameterThe FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, onerror) while permitting others such as 'onmouseenter', combined with the failure to escape… CWE-79Jun 13, 2026 | CVSS6.4v3.1 | EPSS0.301% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |