PT-2026-66699 · WordPress · Lightbox With Photoswipe
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lightbox with PhotoSwipe versions prior to 5.9.0
Description
Insufficient sanitization and escaping of a link data attribute before it is rendered into the image lightbox caption allows users with author-level access and above, who lack the
unfiltered html capability, to perform a stored cross-site scripting attack. This occurs when a visitor or administrator opens the lightbox, executing the stored JavaScript in their browser.Recommendations
Update to version 5.9.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightbox With Photoswipe