PT-2026-28214 · WordPress · Wp Lightbox 2
Krugov Artyom
·
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-1430
CVSS v3.1
4.8
Medium
| AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Lightbox 2 WordPress plugin versions prior to 3.0.7
Description
The WP Lightbox 2 WordPress plugin does not properly sanitise and escape certain settings. This could allow users with high privileges, such as administrators, to carry out Stored Cross-Site Scripting (XSS) attacks. This is possible even when the
unfiltered html capability is disabled, for example, in a multisite configuration. The issue involves insufficient input validation, potentially allowing malicious scripts to be injected and executed within the application.Recommendations
Update WP Lightbox 2 WordPress plugin to version 3.0.7 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Lightbox 2