github.com
https://github.com/fooplugins/foogallery CVE-2024-2081
MEDIUM
FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting
Record summary
CVE-2024-2081 has a selected CVSS score of 6.4 (medium).
Description
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Gallery by FooGalleryBrowse fooplugins / Gallery by FooGalleryDefault status: unaffected | CVE List | Through 2.4.14 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-2081 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3057349%40foogallery&old=3039397%40foogallery&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/e2edeb63-56ad-45e7-9e85-cdf0a8ef41e7?source=cve