VYPR

Simply Gallery Blocks With Lightbox

by WordPress

CVEs (2)

  • CVE-2021-24667MedAug 30, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the…

  • CVE-2026-5743MedJul 11, 2026
    risk 0.00cvss 6.4epss 0.00

    The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping on the sliderMaxHeight block attribute in…