PT-2025-21265 · WordPress · Responsive Lightbox & Gallery
Pierre Rudloff
·
Published
2025-05-15
·
Updated
2025-05-15
·
CVE-2025-3742
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Responsive Lightbox & Gallery WordPress plugin versions prior to 2.5.1
Description:
The issue concerns a Stored Cross-Site Scripting attack. Users with the contributor role and above can exploit this due to the plugin's failure to validate and escape some attributes before outputting them in a page or post.
Recommendations:
For versions prior to 2.5.1, update to version 2.5.1 or later to resolve the issue. As a temporary workaround, consider restricting the contributor role and above to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Responsive Lightbox & Gallery