The LightPress Lightbox WordPress plugin before 2.3.4...
Moderate severity
Unreviewed
Published
May 12, 2025
to the GitHub Advisory Database
•
Updated Jun 5, 2025
Description
Published by the National Vulnerability Database
May 12, 2025
Published to the GitHub Advisory Database
May 12, 2025
Last updated
Jun 5, 2025
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
References