Stored Cross-Site Scripting Vulnerability in FooGallery Plugin for WordPress
CVE-2026-85414
6.4MEDIUM
What is CVE-2026-85414?
The FooGallery plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability through the 'custom_settings' Shortcode Attribute. This flaw, present in all versions up to and including 3.3.2, arises from inadequate input sanitization and output escaping procedures. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts into pages. Consequently, these scripts will execute each time a user accesses the compromised page, potentially compromising users' data and site integrity.
Affected Version(s)
Gallery : FooGallery 0 <= 3.3.2