PT-2024-15135 · WordPress · Foogallery
Colin Xu
·
Published
2024-12-10
·
Updated
2025-02-24
·
CVE-2023-6947
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FooGallery plugin for WordPress versions up to, and including, 2.4.26
Description
The FooGallery plugin for WordPress has a Directory Traversal issue. This allows authenticated attackers with contributor level or higher to read the contents of arbitrary folders on the server, potentially accessing sensitive information such as folder structure.
Recommendations
For versions up to, and including, 2.4.26, update to a version higher than 2.4.26 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive folders on the server until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Foogallery