
GB Gallery Slideshow Security & Risk Analysis
wordpress.org/plugins/gb-gallery-slideshowGB WordPress Gallery Slideshow is Ajax and jquery based plugin. Easy to use slider, which enables you to create customized special effect slideshows.
Is GB Gallery Slideshow Safe to Use in 2026?
High Risk
Score 38/100GB Gallery Slideshow carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The gb-gallery-slideshow plugin exhibits a concerning security posture, primarily due to a significant number of unprotected entry points and a history of recurring vulnerabilities. The static analysis reveals 13 AJAX handlers, with a worrying 8 lacking any authentication checks, creating a broad attack surface susceptible to unauthorized actions. Furthermore, a substantial 45% of SQL queries are not using prepared statements, increasing the risk of SQL injection, especially when combined with the absence of proper output escaping for all identified outputs. The taint analysis, while not revealing critical or high severity unsanitized paths, still flagged 3 flows with unsanitized paths, indicating potential areas for exploitation if combined with other weaknesses.
The vulnerability history paints a clear picture of persistent security flaws. With 3 known CVEs, 2 of which remain unpatched, and a pattern of Cross-site Scripting, Missing Authorization, and SQL Injection vulnerabilities, it's evident that the developers have struggled to address fundamental security issues. The presence of medium severity vulnerabilities that are unpatched is particularly worrying. While the plugin does have some nonces and a reasonable number of SQL queries overall, these strengths are heavily outweighed by the critical weaknesses in authentication and output sanitization. The latest vulnerability being recent further emphasizes the ongoing nature of these security challenges.
Key Concerns
- Unprotected AJAX handlers
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Unpatched CVEs (2 total)
- Missing authorization checks
- Flows with unsanitized paths
GB Gallery Slideshow Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
GB Gallery Slideshow <= 1.3 - Reflected Cross-Site Scripting
GB Gallery Slideshow <= 1.3 - Missing Authorization
GB Gallery Slideshow <= 1.5 - SQL Injection
GB Gallery Slideshow Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GB Gallery Slideshow Attack Surface
AJAX Handlers 13
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
GB Gallery Slideshow Maintenance & Trust
Maintenance Signals
Community Trust
GB Gallery Slideshow Alternatives
Responsive Slider Gallery
responsive-slider-gallery
Build image slideshows with drag-and-drop. A simple responsive slider for posts, pages, and widgets with custom navigation styles.
Gallery Images Ape
gallery-images-ape
Image gallery, responsive photo gallery grid, customizable image slider, simple interface, links, video links and lightbox, custom themes, thumbnails
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
GB Gallery Slideshow Developer Profile
4 plugins · 180 total installs
How We Detect GB Gallery Slideshow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gb-gallery-slideshow/gb-gallery-slideshow.css/wp-content/plugins/gb-gallery-slideshow/gb-gallery-slideshow.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/gbgallery.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/gb-widget.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/css/gb-styles.css/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/jquery.min.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/responsive-slider.min.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/gb-scripts.js/wp-content/plugins/gb-gallery-slideshow/gb-gallery-slideshow.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/gbgallery.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/gb-widget.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/jquery.min.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/responsive-slider.min.js/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/gb-scripts.js/wp-content/plugins/gb-gallery-slideshow/gb-gallery-slideshow.css?ver=/wp-content/plugins/gb-gallery-slideshow/gb-gallery-slideshow.js?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/gbgallery.js?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/gb-widget.js?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/css/gb-styles.css?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/jquery.min.js?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/responsive-slider.min.js?ver=/wp-content/plugins/gb-gallery-slideshow/gbgallery/assets/js/gb-scripts.js?ver=HTML / DOM Fingerprints
gb_widget_congb_small_descgb_premium_asteriskGB_size_conGB_auto_resize_conGB_duration_conGB_effects_conGB_class_con+1 moreid="gb_gallery_shortcode"id="gb_gallery_options"id="gb_gallery_gallery_options"data-id="gb_gallery_gallery_options"gb_gallery_global_data/wp-json/gb-gallery-slideshow/v1/settings[gb_gallery][gb_gallery id=