fooplugins Vulnerabilities and Affected Products
Vulnerabilities associated with lightbox_and_modal_popup.
Products
Clear product- Gallery by FooGallery11 vulnerabilities
- FooGallery4 vulnerabilities
- Lightbox & Modal Popup WordPress Plugin – FooBox4 vulnerabilities
- Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar2 vulnerabilities
- Best Image Gallery & Responsive Photo Gallery – FooGallery1 vulnerability
- Best WordPress Gallery Plugin – FooGallery1 vulnerability
- FooBox Image Lightbox1 vulnerability
- foobox-image-lightbox-premium1 vulnerability
- lightbox_and_modal_popup1 vulnerability
- Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3276MEDIUM | FooBox (Free and Premium) < 2.7.28 - Admin+ Stored XSSThe Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CWE-79Jun 18, 2024 | CVSS6.1v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |