CVE-2023-6947 HIGH

CVE-2023-6947: Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

Vendor Https://Fooplugins.com
Product FooGallery Premium
Weakness CWE-25
Published December 10, 2024
Last update April 8, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure.

Explanation of Vulnerability in Simple Terms

02Summary

FooGallery Premium versions up to 2.4.26 contain an authorization flaw that allows authenticated users with low privileges to read sensitive data from other parts of the site. The vulnerability requires a valid user account but no special interaction. The scope is changed, meaning the impact extends beyond the gallery component itself.

What an attacker can do

03Attacker Capabilities

Read sensitive data from other areas of the site that should be restricted.

Potential impact on your site

04Site Impact

Any registered user can access confidential information they shouldn't see, including data outside the gallery.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site.

Key dates

06Disclosure timeline

December 10, 2024 CVE published
April 8, 2026 Record updated