SecAlerts
f

fooplugins

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 9, 2020 to present

18
Total CVEs
4
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
33/100
low

Severity Distribution

Critical
0
High
4
Medium
14
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
XSS
15
2
Path Traversal
1
3
CSRF
1

Most Affected Products

1. FooPlugins Foogallery Wordpress16
2. FooGallery FooGallery5
3. FooPlugins Foobox Wordpress3
4. FooPlugins FooBox1
5. FooPlugins FooBox Image Lightbox1

Recent Vulnerabilities

See more →
CVE-2025-6068
CVSS 6.4EPSS 0%medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

7/11/2025🔧 No Patch
CVE-2025-5537
CVSS 6.4medium

Lightbox & Modal Popup WordPress Plugin – FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting

7/8/2025
CVE-2025-32139
CVSS 5.9EPSS 0%medium

WordPress Lightbox & Modal Popup WordPress Plugin – FooBox plugin <= 2.7.33 - Cross Site Scripting (XSS) vulnerability

4/10/2025
CVE-2024-12114
CVSS 4.3medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates

3/8/2025
CVE-2024-12119
CVSS 6.4medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size

3/8/2025🔧 No Patch
CVE-2023-6947
CVSS 7.7high

Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

12/10/2024
CVE-2024-3276
CVSS 6.1medium

FooBox (Free and Premium) < 2.7.28 - Admin+ Stored XSS

6/18/2024🔧 No Patch
CVE-2024-2122
CVSS 6.4medium

FooGallery <= 2.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL

6/14/2024
CVE-2024-2762
CVSS 6.3medium

FooGallery < 2.4.15 - Author+ Stored XSS

6/13/2024🔧 No Patch
CVE-2024-2081
CVSS 6.4medium

FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting

4/9/2024🔧 No Patch

Monitor fooplugins in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.