VYPR

Wp Lightbox 2

by WordPress

CVEs (4)

  • CVE-2024-6263MedJul 3, 2024
    risk 0.42cvss 6.4epss 0.00

    The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2025-3745MedJun 30, 2025
    risk 0.41cvss 6.3epss 0.00

    The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

  • CVE-2023-45747MedOct 25, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Syed Balkhi WP Lightbox 2 plugin <= 3.0.6.5 versions.

  • CVE-2026-1430MedMar 26, 2026
    risk 0.31cvss 4.8epss 0.00

    The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…