CVE-2023-6947

HIGH

FooGallery < 2.4.27 - Authenticated Directory Traversal

Title source: llm
STIX 2.1

Description

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure.

Scores

CVSS v3 7.7
EPSS 0.0073
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-25
Status published
Products (2)
fooplugins/foogallery < 2.4.27
https://fooplugins.com/FooGallery Premium < 2.4.26
Published Dec 10, 2024
Tracked Since Feb 18, 2026