PatchSiren

fooplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM fooplugins CVE published 2026-09-05

CVE-2026-85414

The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts, potentially leading to user session hijacking, unauthorized actions, or site defacement. WordPress administ [truncated]

MEDIUM fooplugins CVE published 2026-06-13

CVE-2026-9134

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31. This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, [truncated]