Impact
The Fullscreen Galleria plugin for WordPress contains an unsanitized 'href' attribute in post content that is directly interpolated into an SQL query. This weakness allows an attacker with contributor or higher permissions to inject additional SQL statements. The consequence is the unauthorized extraction of sensitive database content, compromising confidentiality. The flaw is based on CWE-89 and is rated moderate severity with a CVSS score of 6.5.
Affected Systems
WordPress sites running the Fullscreen Galleria plugin by pdamsten, versions up to and including 1.6.12. Any deployment of these versions is affected.
Risk and Exploitability
The risk is moderate, as the attacker requires authenticated contributor-level access. No exploitation requires network-level interaction beyond normal user permissions. The CVSS score of 6.5 reflects potential confidentiality impact. Because EPSS is unavailable, the likelihood of current exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Deployment of older versions with contributor roles therefore presents a real threat for potential data theft.
OpenCVE Enrichment