cve-2025-6068

MEDIUM CVSS 6.4 opencve
Description

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Timeline
Published
2025-07-11 08:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 6.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N mitre
3.1 6.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N nvd
3.1 6.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "EUVD-2025-21116",
      "source": "euvd",
      "title": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21116"
    }
  ],
  "cve": "CVE-2025-6068",
  "enrichment": {
    "analysis": {
      "en": {
        "generated_at": "2026-04-21T19:44:55.717988+00:00",
        "value": {
          "mitigation_remediation": [
            "Upgrade Foogallery to a version newer than 2.4.31.",
            "Temporarily reduce Contributor or higher role privileges until the plugin is updated, or review role permissions to minimize exposure.",
            "If a patch is not yet available, restrict access to the gallery editor to trusted users only."
          ],
          "summary": {
            "action": "Patch Now",
            "impact": "Stored Cross‑Site Scripting in the Foogallery WordPress plugin"
          },
          "threat_synthesis": {
            "affected_systems": "The vulnerability affects WordPress installations running Foogallery plugin versions 2.4.31 and earlier under the vendor Fooplugins: Gallery by Foogallery.",
            "description_and_impact": "The Foogallery plugin contains a stored cross‑site scripting vulnerability that allows authenticated contributors to inject arbitrary web scripts through the `data-caption-title` and `data-caption-description` attributes. The input is insufficiently sanitized or escaped, so the malicious script will execute in any visitor’s browser when the gallery page containing the injected content is loaded, resulting in client‑side code execution on site visitors.",
            "risk_and_exploitability": "The CVSS score of 6.4 classifies the flaw as moderate, while an EPSS score of less than 1 % indicates a low immediate exploitation probability. The flaw is not listed in the CISA KEV catalog. The vulnerability requires authenticated Contributor or higher access; if credentials are obtained, the injected script will run for all users who view the vulnerable gallery page."
          }
        }
      }
    },
    "created": "2026-04-21T19:45:16.083129+00:00",
    "updated": "2026-04-21T19:45:16.083146+00:00",
    "vendors": []
  },
  "epss": {
    "score": 0.00217
  },
  "mitre": {
    "cpes": [],
    "created": "2025-07-11T07:23:00.715000+00:00",
    "description": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.4,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2025/6xxx/CVE-2025-6068.json",
    "references": [
      "https://plugins.trac.wordpress.org/browser/foogallery/trunk/extensions/default-templates/shared/js/foogallery.min.js",
      "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3322251%40foogallery&new=3322251%40foogallery&sfp_email=&sfph_mail=",
      "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6be4aaa-f8a1-42d6-95c1-062c5ca51004?source=cve"
    ],
    "title": "FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting",
    "updated": "2026-04-08T17:13:33.722000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-79"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:fooplugins:foogallery:*:*:*:*:-:wordpress:*:*"
    ],
    "created": "2025-07-11T08:15:24.280000+00:00",
    "description": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.4,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2025/CVE-2025-6068.json",
    "references": [
      "https://plugins.trac.wordpress.org/browser/foogallery/trunk/extensions/default-templates/shared/js/foogallery.min.js",
      "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3322251%40foogallery&new=3322251%40foogallery&sfp_email=&sfph_mail=",
      "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6be4aaa-f8a1-42d6-95c1-062c5ca51004?source=cve"
    ],
    "title": null,
    "updated": "2026-06-17T10:01:05.313000+00:00",
    "vendors": [
      "fooplugins",
      "fooplugins$PRODUCT$foogallery"
    ],
    "weaknesses": [
      "CWE-79"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-07-11T07:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-79"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/extensions/default-templates/shared/js/foogallery.min.js",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3322251%40foogallery&new=3322251%40foogallery&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6be4aaa-f8a1-42d6-95c1-062c5ca51004?source=cve"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6.4,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "9e32d127-0597-4c00-a18e-481bff392c5d"
      },
      {
        "created": "2025-07-11T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "epss": {
                  "score": 0.00029
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "7d9311a8-954f-4ca6-b089-001059cda742"
      },
      {
        "created": "2025-07-11T17:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "296cc284-29a5-4817-b994-1057946f6746"
      },
      {
        "created": "2025-07-17T13:15:00+00:00",
        "data": [
          {
            "details": [
              "fooplugins",
              "fooplugins$PRODUCT$foogallery"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:fooplugins:foogallery:*:*:*:*:-:wordpress:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "fooplugins",
                "fooplugins$PRODUCT$foogallery"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "b295a728-6237-48d9-9444-c72733a0c48a"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:fooplugins:foogallery:*:*:*:*:-:wordpress:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2025-07-11T07:23:00.715000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6.4,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00217
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://plugins.trac.wordpress.org/browser/foogallery/trunk/extensions/default-templates/shared/js/foogallery.min.js",
        "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3322251%40foogallery&new=3322251%40foogallery&sfp_email=&sfph_mail=",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6be4aaa-f8a1-42d6-95c1-062c5ca51004?source=cve"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-21T19:45:16.083146+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "fooplugins",
        "fooplugins$PRODUCT$foogallery"
      ],
      "providers": [
        "nvd"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-79"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-07-11T07:23:00.715000+00:00",
    "description": "The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML attributes in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting",
    "updated": "2025-07-11T16:52:18.469000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/6xxx/CVE-2025-6068.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON