Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
medium
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contrib...
- CVSS:
- 6.4
- Affected:
- up to 9.10.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 19, 2025
CVE-2025-5092 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] >= 9.8.1 - <= 9.8.4
unknown
[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web...
- Affected:
- 9.8.1 – 9.8.4
- Fixed in:
- 9.8.4
- Disclosed:
- Dec 13, 2022
CVE-2022-4207 on NVD →
Image Hover Effects Ultimate 9.8.1 - 9.8.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...
- CVSS:
- 5.5
- Affected:
- 9.8.1 – 9.8.4
- Fixed in:
- 9.8.5
- Disclosed:
- Dec 11, 2022
CVE-2022-4207 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.2
unknown
[en] Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
- Affected:
- up to 9.7.2
- Fixed in:
- 9.7.2
- Disclosed:
- Nov 18, 2022
CVE-2022-42459 on NVD →
Image Hover Effects Ultimate <= 9.7.1 - Authenticated (Admin+) Arbitrary Options Update
high
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and including, 9.7.1. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This makes it possible for authenticated attackers, with administrative level permiss...
- CVSS:
- 7.2
- Affected:
- up to 9.7.1
- Fixed in:
- 9.7.2
- Disclosed:
- Oct 25, 2022
CVE-2022-42459 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0
unknown
[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 9.8.0
- Fixed in:
- 9.8.0
- Disclosed:
- Sep 23, 2022
CVE-2022-2937 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0
unknown
[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- Affected:
- up to 9.8.0
- Fixed in:
- 9.8.0
- Disclosed:
- Sep 6, 2022
CVE-2022-2935 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.8.0
unknown
[en] The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inje...
- Affected:
- up to 9.8.0
- Fixed in:
- 9.8.0
- Disclosed:
- Sep 6, 2022
CVE-2022-2936 on NVD →
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Media URL
medium
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to i...
- CVSS:
- 6.4
- Affected:
- up to 9.7.3
- Fixed in:
- 9.8.0
- Disclosed:
- Aug 31, 2022
CVE-2022-2935 on NVD →
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Video Link
medium
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 9.7.3
- Fixed in:
- 9.8.0
- Disclosed:
- Aug 31, 2022
CVE-2022-2936 on NVD →
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & Description
medium
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 9.7.3
- Fixed in:
- 9.8.0
- Disclosed:
- Aug 31, 2022
CVE-2022-2937 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.2
unknown
[en] Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress.
- Affected:
- up to 9.7.2
- Fixed in:
- 9.7.2
- Disclosed:
- May 20, 2022
CVE-2022-29424 on NVD →
Image Hover Effects Ultimate <= 9.7.1 - Reflected Cross-Site Scripting
medium
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress. Please note that this is separate from CVE-2021-25031.
- CVSS:
- 6.1
- Affected:
- up to 9.7.1
- Fixed in:
- 9.7.2
- Disclosed:
- May 4, 2022
CVE-2022-29424 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.1
unknown
[en] The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 9.7.1
- Fixed in:
- 9.7.1
- Disclosed:
- Jan 24, 2022
CVE-2021-25031 on NVD →
Image Hover Effects Ultimate <= 9.7.0 - Reflected Cross-Site Scripting via effects
medium
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 9.7.0
- Fixed in:
- 9.7.1
- Disclosed:
- Dec 27, 2021
CVE-2021-25031 on NVD →
Image Hover Effects Ultimate <= 9.6.1 - Unauthenticated Arbitrary Options Update
critical
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
- CVSS:
- 9.8
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.2
- Disclosed:
- Dec 15, 2021
CVE-2021-36888 on NVD →
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) [image-hover-effects-ultimate] < 9.7.0
unknown
[en] Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
- Affected:
- up to 9.7.0
- Fixed in:
- 9.7.0
- Disclosed:
- Dec 15, 2021
CVE-2021-36888 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database