VYPR
Unrated severityNVD Advisory· Published May 12, 2025· Updated May 12, 2025

LightPress Lightbox < 2.3.4 - Contributor+ Stored XSS

CVE-2025-3649

Description

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.