Fullscreen Galleria Plugin Vulnerability (CVE-2026-16079)

On this page

Security Alert Summary

The Fullscreen Galleria plugin for WordPress contains a SQL injection vulnerability in how it handles the href attribute in post content. Authenticated users with contributor-level access or higher can inject additional SQL into existing queries, which can be used to extract sensitive data from the database.

CVE Details

  • CVE ID: CVE-2026-16079
  • Affected plugin: Fullscreen Galleria (WordPress plugin)
  • Affected versions: All versions up to and including 1.6.12
  • Published: August 16, 2026 at 5:16:47 AM
  • Last modified: August 16, 2026 at 5:16:47 AM
  • CVSS v3.1: Base Score 6.5; Severity MEDIUM; Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Authentication / privileges / user interaction: Requires authentication (low privileges required). No user interaction required.
  • Primary impact: Confidentiality: High; Integrity: None; Availability: None
  • Weakness: CWE-89 (SQL Injection)

Technical Details

The plugin fails to sufficiently escape a user-supplied parameter coming from the href attribute in post content and does not properly prepare the existing SQL query. This lack of escaping and query preparation allows authenticated users with contributor-level access or higher to append additional SQL statements to an existing query.

Because the vulnerability is an SQL injection (CWE-89), an attacker who can insert crafted content into a post href can cause the database to return unintended data. The description indicates the issue is rooted in insufficient escaping and inadequate preparation of the SQL query; specific functions or endpoints are not named in the provided data.

Impact is limited to data exposure through crafted SQL queries; there is no indication in the provided data that integrity or availability are affected.

How This Could Impact Your Website

Consider a site with multiple users: a site owner, internal staff who publish content, and an external contractor with contributor access. If a contributor can add or edit post content, they could embed a crafted href that causes the plugin to execute additional SQL and return sensitive data. Realistic consequences include exposure of internal user email addresses or other confidential records stored in the database, which raises the risk of targeted phishing or social engineering against staff.

If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.

Recommended Actions

  • Update the affected plugin as soon as a patched version is available.
  • Review and reduce unnecessary user roles, especially contributor-level accounts that can edit post content.
  • Enforce strong passwords and enable two-factor authentication for editors and administrators.
  • Remove unused or unmaintained plugins.
  • Monitor site activity and logs for unusual behavior or unexpected database queries.

If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.


References