PT-2025-20681 · WordPress+1 · Firelight Lightbox+1

Pierre Rudloff

·

Published

2025-05-12

·

Updated

2025-05-12

·

CVE-2025-3597

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Firelight Lightbox plugin for WordPress versions prior to 2.3.15
Description The issue allows users with post writing capabilities to execute arbitrary JavaScript when the jQuery Metadata library is enabled. This feature is intended for Pro version users but can also be activated in the free version, making it theoretically exploitable.
Recommendations For Firelight Lightbox plugin for WordPress versions prior to 2.3.15, update to version 2.3.15 or later to resolve the issue. As a temporary workaround, consider disabling the jQuery Metadata library until a patch is available. Restrict access to users with post writing capabilities to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2025-3597

Affected Products

Firelight Lightbox
Jquery Metadata