VYPR

Fancybox

by Colorlib

CVEs (3)

  • CVE-2025-3662MedJun 3, 2025
    risk 0.40cvss 6.1epss 0.00

    The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an…

  • CVE-2024-0662MedApr 9, 2024
    risk 0.29cvss 4.4epss 0.00

    The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

  • CVE-2015-1494Feb 17, 2015
    risk 0.00cvss epss 0.06

    The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the…