Gallery by FooGallery

Vulnerabilities 30Slug foogalleryLatest version 3.1.26WordPress.org →

Minimum safe version

3.1.13

Update to 3.1.13 or later to address 30 fixable vulnerabilities

Latest available3.1.26
Medium 6.4
2025-07-11< 2.4.32

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Medium 5.1
2025-03-04< 2.4.30

WordPress FooGallery Plugin <= 2.4.29 is vulnerable to Cross Site Scripting (XSS)

Medium 6.3
2024-10-16< 2.1.34

Freemius SDK <= 2.4.2 - Missing Authorization Checks

N/A
2023-07-18< 2.2.44

WordPress FooGallery Plugin < 2.2.44 is vulnerable to Cross Site Scripting (XSS)

N/A
< 1.9.25

FooGallery &lt; 1.9.25 - Authenticated Cross-Site Scripting (XSS)

N/A
2019-02-25< 1.6.17

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

N/A
2020-05-04< 1.9.25

FooGallery <= 1.9.24 - Authenticated Cross-Site Scripting

N/A
2022-03-04< 2.1.34

Freemius SDK <= 2.4.2 - Missing Authorization Checks

N/A
< 1.6.17

Freemius Library &lt; 2.2.4 - Subscriber+ Arbitrary Option Update

N/A
< 2.1.34

Unauthorised AJAX Calls via Freemius

N/A
2019-03-02< 1.6.17

WordPress FooGallery plugin <= 1.6.15 - Authenticated Option Update vulnerability (Fremius Library security issue)

N/A
2020-08-27< 1.9.25

WordPress FooGallery plugin <= 1.9.24 - Authenticated Cross-Site Scripting (XSS) vulnerability

N/A
2022-02-28< 2.1.34

WordPress FooGallery plugin <= 2.1.33 - Sensitive Information Disclosure vulnerability

N/A
2022-02-28< 2.1.34

WordPress FooGallery plugin <= 2.1.33 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability

Medium 4.8
2020-06-01< 1.8.18

FooGallery <= 1.8.12 - Cross-Site Scripting