🔐 CVE Alert

CVE-2023-6947

HIGH 7.7

Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure.

CWE CWE-25
Vendor https://fooplugins.com
Product foogallery premium
Published Dec 10, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for https://fooplugins.com foogallery premium

Be the first to know when new high vulnerabilities affecting https://fooplugins.com foogallery premium are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

https://fooplugins.com / FooGallery Premium
0 ≤ 2.4.26

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/68420c5a-4add-4597-bd2a-20dc831e81bd?source=cve github.com: https://github.com/fooplugins/foogallery/pull/263/commits/9989f6f4f4d478ec04cb634d09b18c87a5b31c4d

Credits

Colin Xu