What is CVE-2026-16079?
The Fullscreen Galleria plugin for WordPress up to version 1.6.12 is vulnerable to SQL Injection via the 'href' attribute in post content. Insufficient escaping and lack of SQL query preparation allow unauthenticated attackers to interfere with the database. It is recommended to immediately update the plugin to the latest version.
Azərbaycanca: Fullscreen Galleria WordPress plaqini (1.6.12 və daha əvvəl versiyalar) post məzmunundakı 'href' atributu vasitəsilə SQL Injection zəifliyinə məruz qalır. İstifadəçi tərəfindən daxil edilən parametrin zəif escapelənməsi və SQL sorğusunun hazırlanmaması səbəbindən autentifikasiya olunmamış hücumçular verilənlər bazasına müdaxilə edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Fullscreen Galleria WordPress plugin are affected by the SQL Injection vulnerability?
The vulnerability affects the plugin up to version 1.6.12.
Does an attacker need to be authenticated to exploit this vulnerability?
No, insufficient escaping allows unauthenticated attackers to exploit this vulnerability via the 'href' attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.