Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute
medium
The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-c...
- CVSS:
- 6.4
- Affected:
- up to 2.3.20
- Fixed in:
- 2.3.21
- Disclosed:
- Jul 23, 2026
CVE-2026-6454 on NVD →
Firelight Lightbox [easy-fancybox] < 2.3.17
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS. This issue affects Firelight Lightbox: from n/a through 2.3.16.
- Affected:
- up to 2.3.17
- Fixed in:
- 2.3.17
- Disclosed:
- Jun 20, 2025
CVE-2025-52707 on NVD →
Firelight Lightbox <= 2.3.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 6.4
- Affected:
- up to 2.3.16
- Fixed in:
- 2.3.17
- Disclosed:
- Jun 19, 2025
CVE-2025-52707 on NVD →
Firelight Lightbox < 2.3.17 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
- Affected:
- up to 2.3.17
- Fixed in:
- 2.3.17
- Disclosed:
- Jun 19, 2025
CVE-2025-52707 on NVD →
Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.15 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 2.3.15
- Fixed in:
- 2.3.16
- Disclosed:
- Jun 6, 2025
CVE-2025-5035 on NVD →
Firelight Lightbox < 2.3.16 - Contributor+ Stored XSS
medium
- Affected:
- up to 2.3.16
- Fixed in:
- 2.3.16
- Disclosed:
- Jun 6, 2025
CVE-2025-5035 on NVD →
Firelight Lightbox <= 2.3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.14 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 2.3.14
- Fixed in:
- 2.3.15
- Disclosed:
- Apr 21, 2025
CVE-2025-3597 on NVD →
Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS
medium
- Affected:
- up to 2.3.15
- Fixed in:
- 2.3.15
- Disclosed:
- Apr 21, 2025
CVE-2025-3597 on NVD →
Firelight Lightbox [easy-fancybox] < 2.3.4
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Multiple Plugins - Contributor+ DOM-Based Stored XSS via FancyBox JavaScript Library
medium
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Firelight Lightbox [easy-fancybox] < 2.3.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS.This issue affects Firelight Lightbox: from n/a through 2.3.3.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Oct 28, 2024
CVE-2024-50460 on NVD →
Firelight Lightbox <= 2.3.3 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Oct 24, 2024
CVE-2024-50460 on NVD →
Firelight Lightbox < 2.3.4 - Authenticated (Author+) Stored Cross-Site Scripting
medium
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Oct 24, 2024
CVE-2024-50460 on NVD →
Firelight Lightbox [easy-fancybox] < 1.8.18
unknown
[en] The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
- Affected:
- up to 1.8.18
- Fixed in:
- 1.8.18
- Disclosed:
- Sep 26, 2019
CVE-2019-16524 on NVD →
Easy Fancybox <= 1.8.17 - Authenticated Stored Cross-Site Scripting
medium
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
- CVSS:
- 5.5
- Affected:
- up to 1.8.17
- Fixed in:
- 1.8.18
- Disclosed:
- Sep 25, 2019
CVE-2019-16524 on NVD →
Easy Fancybox < 1.8.18 - Authenticated Stored XSS
medium
- Affected:
- up to 1.8.18
- Fixed in:
- 1.8.18
- Disclosed:
- Sep 25, 2019
CVE-2019-16524 on NVD →
Firelight Lightbox [easy-fancybox] < 2.3.15
unknown
- Affected:
- up to 2.3.15
- Fixed in:
- 2.3.15
CVE-2025-3597 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database