plugin

Easy Fancybox Vulnerabilities

18 known security issues reported for the Easy Fancybox WordPress plugin. Most recent disclosed Jul 23, 2026.

13 medium

Running Easy Fancybox on your site? Check whether your installed version is affected.

Scan your site free

Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute

medium

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-c...

CVSS:
6.4
Affected:
up to 2.3.20
Fixed in:
2.3.21
Disclosed:
Jul 23, 2026

CVE-2026-6454 on NVD →

Firelight Lightbox [easy-fancybox] < 2.3.17

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS. This issue affects Firelight Lightbox: from n/a through 2.3.16.

Affected:
up to 2.3.17
Fixed in:
2.3.17
Disclosed:
Jun 20, 2025

CVE-2025-52707 on NVD →

Firelight Lightbox <= 2.3.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 2.3.16
Fixed in:
2.3.17
Disclosed:
Jun 19, 2025

CVE-2025-52707 on NVD →

Firelight Lightbox < 2.3.17 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium
Affected:
up to 2.3.17
Fixed in:
2.3.17
Disclosed:
Jun 19, 2025

CVE-2025-52707 on NVD →

Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.15 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-lev...

CVSS:
6.4
Affected:
up to 2.3.15
Fixed in:
2.3.16
Disclosed:
Jun 6, 2025

CVE-2025-5035 on NVD →

Firelight Lightbox < 2.3.16 - Contributor+ Stored XSS

medium
Affected:
up to 2.3.16
Fixed in:
2.3.16
Disclosed:
Jun 6, 2025

CVE-2025-5035 on NVD →

Firelight Lightbox <= 2.3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.14 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-lev...

CVSS:
6.4
Affected:
up to 2.3.14
Fixed in:
2.3.15
Disclosed:
Apr 21, 2025

CVE-2025-3597 on NVD →

Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS

medium
Affected:
up to 2.3.15
Fixed in:
2.3.15
Disclosed:
Apr 21, 2025

CVE-2025-3597 on NVD →

Firelight Lightbox [easy-fancybox] < 2.3.4

unknown

[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Dec 4, 2024

CVE-2024-5020 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Multiple Plugins - Contributor+ DOM-Based Stored XSS via FancyBox JavaScript Library

medium
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

Firelight Lightbox [easy-fancybox] < 2.3.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS.This issue affects Firelight Lightbox: from n/a through 2.3.3.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Oct 28, 2024

CVE-2024-50460 on NVD →

Firelight Lightbox <= 2.3.3 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Oct 24, 2024

CVE-2024-50460 on NVD →

Firelight Lightbox < 2.3.4 - Authenticated (Author+) Stored Cross-Site Scripting

medium
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Oct 24, 2024

CVE-2024-50460 on NVD →

Firelight Lightbox [easy-fancybox] < 1.8.18

unknown

[en] The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

Affected:
up to 1.8.18
Fixed in:
1.8.18
Disclosed:
Sep 26, 2019

CVE-2019-16524 on NVD →

Easy Fancybox <= 1.8.17 - Authenticated Stored Cross-Site Scripting

medium

The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

CVSS:
5.5
Affected:
up to 1.8.17
Fixed in:
1.8.18
Disclosed:
Sep 25, 2019

CVE-2019-16524 on NVD →

Easy Fancybox < 1.8.18 - Authenticated Stored XSS

medium
Affected:
up to 1.8.18
Fixed in:
1.8.18
Disclosed:
Sep 25, 2019

CVE-2019-16524 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database