WordPress Plugin Vulnerabilities

Responsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSS

Description

The plugin use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Proof of Concept

Affects Plugins

Fixed in 2.5.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes

Timeline

Publicly Published
2025-06-06 (about 6 months ago)
Added
2025-06-06 (about 6 months ago)
Last Updated
2025-06-06 (about 6 months ago)

Other