PT-2026-66699 · WordPress · Lightbox With Photoswipe

·

CVE-2026-14833

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lightbox with PhotoSwipe versions prior to 5.9.0
Description Insufficient sanitization and escaping of a link data attribute before it is rendered into the image lightbox caption allows users with author-level access and above, who lack the unfiltered html capability, to perform a stored cross-site scripting attack. This occurs when a visitor or administrator opens the lightbox, executing the stored JavaScript in their browser.
Recommendations Update to version 5.9.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14833

Affected Products

Lightbox With Photoswipe