PT-2026-28214 · WordPress · Wp Lightbox 2

Krugov Artyom

·

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-1430

CVSS v3.1

4.8

Medium

AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Lightbox 2 WordPress plugin versions prior to 3.0.7
Description The WP Lightbox 2 WordPress plugin does not properly sanitise and escape certain settings. This could allow users with high privileges, such as administrators, to carry out Stored Cross-Site Scripting (XSS) attacks. This is possible even when the unfiltered html capability is disabled, for example, in a multisite configuration. The issue involves insufficient input validation, potentially allowing malicious scripts to be injected and executed within the application.
Recommendations Update WP Lightbox 2 WordPress plugin to version 3.0.7 or later.

Exploit

Fix

Related Identifiers

CVE-2026-1430

Affected Products

Wp Lightbox 2