Fooplugins develops a focused line of WordPress gallery and lightbox plugins that serve a broad audience of content creators and website builders. The vendor's vulnerability profile centers on web application input-handling and access-control weaknesses—including cross-site scripting, cross-site request forgery, path traversal, and authorization bypass—that recur across its FooGallery and FooBox products and reflect the plugin's user-facing and file-serving role. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fooplugins over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29439MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. | May 16, 2023 | 6.1 | 30 | NO | YES |
CVE-2023-44233HIGH Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions. | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-6947HIGH The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for au | Dec 10, 2024 | 7.7 | 22 | NO | NO |
CVE-2026-25362MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGalle | Feb 19, 2026 | 5.9 | 20 | NO | NO |
CVE-2021-24357MEDIUM In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before | Jun 14, 2021 | 5.4 | 19 | NO | NO |
CVE-2019-20182MEDIUM The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. | Jan 9, 2020 | 4.8 | 19 | NO | NO |
CVE-2025-6068MEDIUM The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title | Jul 11, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-5537MEDIUM The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions up to, and includ | Jul 8, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-2122MEDIUM The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, | Jun 14, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-2762MEDIUM The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them b | Jun 13, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fooplugins.
Media articles that mention a CVE ID that affects a product developed by Fooplugins — matched by CVE ID, not by vendor name.