Releases26
Frequency3 months 4 weeks
Last Release
Downloads15K

jAlbum Bridge: Add stunning slideshows and grid galleries from jAlbum to your WordPress posts and pages. It’s responsive and mobile-friendly.

Slideshow transition types:

  • Cross-fade
  • Zoom
  • Ken Burns
  • Slide
  • Swap
  • Stack
  • Flip (3D)
  • Carousel (3D)
  • Book (3D)
  • Cube (3D)
  • Cover flow (3D)

Grid-type layouts:

  • Grid
  • Mosaic
  • Strip
  • Masonry

Please note that this projector pulls data from a JSON file, which is automatically generated when you make albums with database-driven skins (Tiger, Photoblogger, Projector, Lizard, or Story). However, you can also ask jAlbum to generate this file with any skin; see “Settings / Advanced / Generate JSON data.” (Don’t forget to “Make album” and “Upload” after turning this option on.)

If you’re using the album from another site, make sure this site supports Cross Origin Resource Sharing (CORS); otherwise, the projector’s access will be blocked. Note that if the WordPress site is under https, the album site must support HTTPS protocol, too!

jAlbum is an album creator desktop application that creates web albums of images on your hard disk. This way, you can manage your photo collection from your PC without needing individual uploads to a remote server.

  • Create albums with folders, custom pages, and external links
  • No limit; you can use tens of thousands of images or videos
  • jAlbum manages the uploads: you can upload to any site (different from your WP site), or you can host them on jalbum.net if you wish
  • Widely customizable albums
  • Tons of features: Google Maps, PayPal cart, Feedback, search, etc.

For help with the plugin, visit your-site-here.com

Read more about jAlbum features

Get the jAlbum application from here

jAlbum Bridge forum on jalbum.net

Feedback is welcome, especially the positive 😉

CVE History

CVEPublishedCVSS v3CVSS v2
6.4 MEDIUM

The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It was determined that the patch in 2.0.16 was insufficient, and 2.0.17 is considered the fully patched version.