Medium severity5.9NVD Advisory· Published Apr 6, 2023· Updated Jun 17, 2026
CVE-2023-24004
CVE-2023-24004
Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wpdevart:download_image_and_video_lightbox\,_image_popup:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:wpdevart:download_image_and_video_lightbox\,_image_popup:*:*:*:*:*:wordpress:*:*range: <2.1.6
- (no CPE)range: n/a
- Range: <=2.1.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.