CVE-2023-6947: Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain sensitive information such as folder structure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6947?
CVE-2023-6947 is rated as a critical vulnerability due to its potential to allow authenticated attackers to exploit directory traversal.
How do I fix CVE-2023-6947?
To fix CVE-2023-6947, update the FooGallery plugin to version 2.4.27 or later.
Who does CVE-2023-6947 affect?
CVE-2023-6947 affects all versions of the FooGallery plugin for WordPress up to and including version 2.4.26.
What type of attack is possible with CVE-2023-6947?
CVE-2023-6947 allows authenticated attackers to perform directory traversal attacks and read arbitrary files on the server.
What permissions are required to exploit CVE-2023-6947?
Exploitation of CVE-2023-6947 requires user permissions of contributor level or higher.