Stored Cross-Site Scripting Vulnerability in FooGallery Plugin for WordPress
CVE-2024-12119
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-12119?
The FooGallery plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the default_gallery_title_size parameter, affecting all versions up to and including 2.4.29. Due to inadequate input sanitization and output escaping processes, authenticated users with roles such as gallery and album creators can exploit this flaw. Attackers can inject malicious web scripts into webpage elements, which will execute automatically when users access an affected page. This poses a significant risk to site visitors and could lead to unauthorized exposure of sensitive user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FooGallery β Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel * <= 2.4.29
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved