CVE-2026-16079

Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 550 live websites that are affected by CVE-2026-16079.

Run a Free Instant Scan




Affected Software

Product  Fullscreen Galleria
Category Wordpress Plugins
Vulnerable Domains550 live websites (100% of Fullscreen Galleria install base)
Vulnerable Versions
  • from 0 through 1.6.12
Vulnerable Versions Count22 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-16079
United States88 websites



Italy95 websites
Germany78 websites
Poland47 websites
France32 websites
Switzerland21 websites
Netherlands20 websites
Russia19 websites
GB19 websites
Slovakia13 websites

Website Distribution by TLD

Number of websites using CVE-2026-16079
.com163 websites
.it69 websites
.de46 websites
.pl38 websites
.org20 websites
.nl19 websites
.net17 websites
.co.uk16 websites
.ru15 websites
.ch15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16079

Top websites that are affected by CVE-2026-16079. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.fr France***,***
******.online Italy***,***
************.com Finland***,***
*****.******.edu United States***,***
****************.com United States***,***
*******.org Germany*,***,***
********.net Spain*,***,***
****.cz Czech Republic*,***,***
*****************.org France*,***,***
*******************.de Germany*,***,***
See full domain list

FAQ

CVE-2026-16079 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fullscreen Galleria
A total of 550 websites have been identified as vulnerable to CVE-2026-16079, based on global website indexing conducted by WebTechSurvey.
The Fullscreen Galleria is affected by the CVE-2026-16079 vulnerability.
Fullscreen Galleria versions up to and including 1.6.12 are vulnerable to CVE-2026-16079.

References