Executive brief
The LightPress Lightbox plugin for WordPress, which is used to display images in a popup overlay, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'group' attribute within the '[gallery]' shortcode. The vulnerability exists in versions up to and including 2.3.4. An authenticated attacker with Contributor-level permissions or higher can exploit this by crafting a shortcode that includes malicious JavaScript. When the gallery is rendered, the script is stored on the page and executes in the context of any user's browser session who visits that page. The issue was addressed in version 2.3.5.
Affected products
- firelightwp LightPress Lightbox <= 2.3.4
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 2.3.5
References
- https://plugins.trac.wordpress.org/browser/wp-jquery-lightbox/tags/2.3.4/lightboxes/wp-jquery-lightbox/class-wp-jquery-lightbox.php
- https://plugins.trac.wordpress.org/browser/wp-jquery-lightbox/tags/2.3.4/lightboxes/wp-jquery-lightbox/class-wp-jquery-lightbox.php
- https://plugins.trac.wordpress.org/changeset?old_path=/wp-jquery-lightbox/tags/2.3.4&new_path=/wp-jquery-lightbox/tags/2.3.5
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2bed4818-70c5-40b7-8d8d-f43f3baa0f3d?source=cve