CVE-2025-6068 carries a CVSS 3.1 base score of 6.4 against FooGallery, a WordPress photo gallery and image viewer plugin by fooplugins. NVD classifies it as CWE-79 (Cross-Site Scripting) and states the flaw affects all versions up to and including 2.4.31. VulnCheck’s KEV feed reports the CVE as exploited, dated September 7, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2025-6068 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the plugin’s data-caption-title and data-caption-description HTML attributes are not properly sanitized on input or escaped on output. An authenticated attacker with Contributor-level access or above can inject arbitrary web scripts into these caption fields; the script executes in the browser of any user who later views a page containing the affected gallery.
Evidence and confidence
- Medium confidence — the CVSS 6.4 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N), the CWE-79 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a Wordfence Threat Intelligence advisory cited in NVD’s own reference list. The exploitation report traces to VulnCheck KEV alone. - Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00217, a 12.3rd percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field beyond NVD’s statement that versions up to and including 2.4.31 are affected.
Why this matters
Stored XSS reachable from a Contributor-level account is a meaningful privilege-escalation path on any WordPress site with open or loosely vetted registration for contributors — the CVSS vector’s Changed scope (S:C) reflects that the injected script can affect the security context of other users beyond the attacker’s own account, including editors and administrators who view the same gallery page. Sites that allow guest contributor submissions or multi-author publishing should treat this as more than a low-trust edge case.
Frequently Asked Questions
What is CVE-2025-6068? A CVSS 6.4 stored cross-site scripting vulnerability (CWE-79) in the FooGallery WordPress plugin by fooplugins, affecting versions up to and including 2.4.31, reachable via unsanitized gallery caption attributes.
Is CVE-2025-6068 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 7, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? Yes. NVD’s description specifies this requires existing Contributor-level access or above — it is not exploitable by a fully unauthenticated visitor.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions up to and including 2.4.31 are affected. Consult the plugin vendor directly for the current patched release.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2025-6068, corroborated by Wordfence’s Threat Intelligence advisory. Exploitation status and the September 7, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.