Fullscreen Galleria

Fullscreen Galleria has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.

Every one of the 2 issues recorded for Fullscreen Galleria has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Fullscreen Galleria is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Fullscreen Galleria vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2026-16079

Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.6.13

Fullscreen Galleria

pdamsten

Author

pdamsten

4.8(15)
96/100
Last Updated
2026-08-05 (1mo ago)
Active Installs
800+
Downloads
107,614
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2012-02-28 (15y ago)

Fullscreen gallery for WordPress. Based on Galleria JavaScript image gallery framework. Features Clean fullscreen interface. Only image and carousel is shown when idle. Custom link support for media eg. link to Flickr page that is shown for the image. If image has gps coordinates it can be shown on map. Usage Use WordPress Gallery feature and media as usual. Images are handled automatically and shown in fullscreen viewer.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C