Unrated severityNVD Advisory· Published May 12, 2025· Updated May 12, 2025
LightPress Lightbox < 2.3.4 - Contributor+ Stored XSS
CVE-2025-3649
Description
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
Affected products
1- Range: <2.3.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/37fb7f3b-1766-4c2c-9b78-f77f15a04476/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.