VYPR

Simplelightbox

by WordPress

Source repositories

CVEs (2)

  • CVE-2024-5878MedMay 20, 2025
    risk 0.35cvss 6.4epss 0.00

    Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2025-3516MedMay 16, 2025
    risk 0.31cvss 5.9epss 0.00

    The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.