What the vulnerability does
01Description
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure.
Explanation of Vulnerability in Simple Terms
02Summary
FooGallery Premium versions up to 2.4.26 contain an authorization flaw that allows authenticated users with low privileges to read sensitive data from other parts of the site. The vulnerability requires a valid user account but no special interaction. The scope is changed, meaning the impact extends beyond the gallery component itself.
What an attacker can do
03Attacker Capabilities
Read sensitive data from other areas of the site that should be restricted.
Potential impact on your site
04Site Impact
Any registered user can access confidential information they shouldn't see, including data outside the gallery.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
December 10, 2024
CVE published
April 8, 2026
Record updated