CVE-2026-85414 | FoolPlugins FooGallery Plugin up to 3.3.2 on WordPress Shortcode custom_settings cross site scripting
A vulnerability classified as problematic was found in FoolPlugins FooGallery Plugin up to 3.3.2 on WordPress. This affects an unknown part of the component Shortcode Handler. Executing a manipulation of the argument custom_settings can lead to cross site scripting.
This vulnerability is registered as CVE-2026-85414. It is possible to launch the attack remotely. No exploit is available.