Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via prettyPhoto JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.12
- Disclosed:
- Jul 2, 2025
CVE-2025-2540 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.9.11
unknown
[en] The WP Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.11
- Disclosed:
- May 2, 2024
CVE-2024-4324 on NVD →
WP Video Lightbox <= 1.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
medium
The WP Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.11
- Disclosed:
- May 1, 2024
CVE-2024-4324 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.9.7
unknown
[en] The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such a...
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- Jan 16, 2023
CVE-2022-4465 on NVD →
WP Video Lightbox <= 1.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Video Lightbox for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping on supplied attributes. This makes it possible for authenticated attackers with contributor-level permissions an...
- CVSS:
- 6.4
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- Dec 21, 2022
CVE-2022-4465 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.9.5
unknown
[en] The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Jul 25, 2022
CVE-2022-2189 on NVD →
Video Lightbox <= 1.9.5 - Authenticated Stored Cross-Site Scripting
medium
The Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with administrator-level permissions and above, to inject arbitrary web scri...
- CVSS:
- 4.8
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Jul 4, 2022
WP Video Lightbox [wp-video-lightbox] < 1.9.6
unknown
The Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with administrator-level permissions and above, to inject arbitrary web scri...
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Jul 4, 2022
WP Video Lightbox [wp-video-lightbox] < 1.9.6
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WP Video Lightbox plugin (versions <= 1.9.5).
Update the WordPress WP Video Lightbox plugin to the latest available version (at least 1.9.6).
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Jul 4, 2022
WP Video Lightbox <= 1.9.4 - Reflected Cross-Site Scripting
medium
The WP Video Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for administrative attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Jun 30, 2022
CVE-2022-2189 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.9.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress WP Video Lightbox plugin (versions <= 1.9.4).
Update the WordPress WP Video Lightbox plugin to the latest available version (at least 1.9.5).
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Jun 30, 2022
WP Video Lightbox [wp-video-lightbox] < 1.9.3
unknown
[en] The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
- Affected:
- up to 1.9.3
- Fixed in:
- 1.9.3
- Disclosed:
- Aug 30, 2021
CVE-2021-24665 on NVD →
WP Video Lightbox <= 1.9.2 - Contributor+ Stored Cross-Site Scripting
medium
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
- CVSS:
- 5.4
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.3
- Disclosed:
- Aug 23, 2021
CVE-2021-24665 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.7.5
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- May 14, 2015
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
- CVSS:
- 6.1
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- Aug 1, 2014
CVE-2013-6837 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.7.5
unknown
[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- Dec 19, 2013
CVE-2013-6837 on NVD →
WP Video Lightbox [wp-video-lightbox] < 1.9.5
unknown
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
WP Video Lightbox [wp-video-lightbox] < 1.9.12
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-...
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database