Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-15524
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15524 is a Missing Authorization vulnerability in the Gallery by FooGallery plugin for WordPress, allowing authenticated attackers with Subscriber-level access or above to access metadata of private, draft, and password-protected galleries. The flaw exists in all versions up to and including 3.1.9 of the plugin. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Vulners).

Technical details

The root cause is a missing capability check (CWE-862) on the ajax_get_gallery_info() function within the FooGallery plugin. Any authenticated user with at least Subscriber-level access can invoke this AJAX function and enumerate gallery IDs to retrieve metadata — including gallery name, image count, and thumbnail URL — for galleries that should be restricted (private, draft, or password-protected). No elevated privileges or user interaction are required beyond basic authentication, and the attack is conducted entirely over the network with low complexity (Red Hat CVE, InfinitSec).

Impact

Exploitation allows low-privileged authenticated users to enumerate and retrieve metadata (name, image count, thumbnail URL) from galleries that site owners intended to keep private, in draft status, or protected by a password. While no direct modification or deletion of data is possible, the confidentiality of unpublished or restricted gallery content is compromised. The scope is limited to the WordPress site hosting the vulnerable plugin, with no known lateral movement potential, but information disclosure could aid further targeted attacks against the site or its users (Red Hat CVE, Sucuri Blog).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-15524. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a registered (Subscriber-level) account on the target WordPress site, limiting opportunistic mass exploitation (Red Hat CVE, Vulners).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Gallery by FooGallery plugin version 3.1.9 or earlier, using tools like WPScan or manual inspection of plugin directories.
  2. Obtain Subscriber Access: Register for a free account on the target WordPress site (if open registration is enabled) or use existing low-privilege credentials.
  3. Craft AJAX Request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter targeting ajax_get_gallery_info and a guessed or sequentially enumerated gallery ID.
  4. Enumerate Gallery IDs: Iterate through numeric gallery IDs to discover private, draft, or password-protected galleries and collect their metadata (name, image count, thumbnail URL).
  5. Collect Disclosed Metadata: Use the returned metadata to map out restricted gallery content, which may inform further attacks or expose sensitive information about unpublished site content (InfinitSec, Red Hat CVE).

Indicators of compromise

  • Network: Repeated authenticated POST requests to /wp-admin/admin-ajax.php with the action parameter set to ajax_get_gallery_info and sequentially incrementing or randomized gallery ID values from a single source IP.
  • Logs: WordPress access logs showing a high volume of AJAX requests to admin-ajax.php from a Subscriber-level user account, particularly with varying gallery ID parameters in rapid succession.
  • Logs: Authentication logs showing a newly registered or low-privilege account making an unusual number of AJAX calls outside of normal user behavior patterns.

Mitigation and workarounds

Update the Gallery by FooGallery WordPress plugin to version 3.2.0 or later, which introduces the required capability check on the ajax_get_gallery_info() function. As a temporary workaround, site administrators can disable open user registration to prevent untrusted users from obtaining Subscriber-level accounts, reducing the attack surface. Regularly auditing installed plugin versions and applying updates promptly is recommended best practice (Red Hat CVE, Sucuri Blog).

Community reactions

Sucuri included CVE-2025-15524 in their February 2026 vulnerability patch roundup, noting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant independent researcher commentary or notable social media discussion has been identified for this vulnerability beyond standard aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management