
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15524 is a Missing Authorization vulnerability in the Gallery by FooGallery plugin for WordPress, allowing authenticated attackers with Subscriber-level access or above to access metadata of private, draft, and password-protected galleries. The flaw exists in all versions up to and including 3.1.9 of the plugin. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Vulners).
The root cause is a missing capability check (CWE-862) on the ajax_get_gallery_info() function within the FooGallery plugin. Any authenticated user with at least Subscriber-level access can invoke this AJAX function and enumerate gallery IDs to retrieve metadata — including gallery name, image count, and thumbnail URL — for galleries that should be restricted (private, draft, or password-protected). No elevated privileges or user interaction are required beyond basic authentication, and the attack is conducted entirely over the network with low complexity (Red Hat CVE, InfinitSec).
Exploitation allows low-privileged authenticated users to enumerate and retrieve metadata (name, image count, thumbnail URL) from galleries that site owners intended to keep private, in draft status, or protected by a password. While no direct modification or deletion of data is possible, the confidentiality of unpublished or restricted gallery content is compromised. The scope is limited to the WordPress site hosting the vulnerable plugin, with no known lateral movement potential, but information disclosure could aid further targeted attacks against the site or its users (Red Hat CVE, Sucuri Blog).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-15524. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a registered (Subscriber-level) account on the target WordPress site, limiting opportunistic mass exploitation (Red Hat CVE, Vulners).
/wp-admin/admin-ajax.php) with the action parameter targeting ajax_get_gallery_info and a guessed or sequentially enumerated gallery ID./wp-admin/admin-ajax.php with the action parameter set to ajax_get_gallery_info and sequentially incrementing or randomized gallery ID values from a single source IP.admin-ajax.php from a Subscriber-level user account, particularly with varying gallery ID parameters in rapid succession.Update the Gallery by FooGallery WordPress plugin to version 3.2.0 or later, which introduces the required capability check on the ajax_get_gallery_info() function. As a temporary workaround, site administrators can disable open user registration to prevent untrusted users from obtaining Subscriber-level accounts, reducing the attack surface. Regularly auditing installed plugin versions and applying updates promptly is recommended best practice (Red Hat CVE, Sucuri Blog).
Sucuri included CVE-2025-15524 in their February 2026 vulnerability patch roundup, noting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant independent researcher commentary or notable social media discussion has been identified for this vulnerability beyond standard aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."