PT-2026-28214 · WordPress · Wp Lightbox 2

Krugov Artyom

·

Publicado

2026-03-26

·

Atualizado

2026-04-07

·

CVE-2026-1430

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Lightbox 2 WordPress plugin versions prior to 3.0.7
Description The WP Lightbox 2 WordPress plugin does not properly sanitise and escape certain settings. This could allow users with high privileges, such as administrators, to carry out Stored Cross-Site Scripting (XSS) attacks. This is possible even when the unfiltered html capability is disabled, for example, in a multisite configuration. The issue involves insufficient input validation, potentially allowing malicious scripts to be injected and executed within the application.
Recommendations Update WP Lightbox 2 WordPress plugin to version 3.0.7 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-1430

Produtos afetados

Wp Lightbox 2