WordPress · Gallery By Foogallery · CVE-2025-15524
**Name of the Vulnerable Software and Affected Versions**
The Gallery by FooGallery plugin for WordPress versions through 3.1.9
**Description**
The Gallery by FooGallery plugin for WordPress has a flaw that allows unauthorized access to data. A missing capability check in the `ajax get gallery info()` function permits authenticated attackers with Subscriber-level access or higher to retrieve metadata—including the name, image count, and thumbnail URL—of private, draft, and password-protected galleries by enumerating gallery IDs.
**Recommendations**
Update to a version of The Gallery by FooGallery plugin later than 3.1.9.