Junglewise Threat Intelligence

CVE-2026-6454: Firelight Lightbox Stored DOM XSS in PDF Callback

CVE-2026-6454 · Severity: medium · CVSS 6.4 · Published 2026-07-24

Executive brief

The Firelight Lightbox plugin for WordPress, which is used to display images and PDFs in professional overlay windows, contains a security flaw. An attacker with contributor-level access can inject malicious scripts into PDF links. When other users or administrators click these links, the script executes in their browser, potentially allowing the attacker to steal session information or perform unauthorized actions on the site.

Technical details

The Firelight Lightbox plugin (also known as Easy FancyBox) is vulnerable to Stored DOM Cross-Site Scripting (XSS) due to improper sanitization of the 'href' attribute within the FancyBox V2 PDF 'beforeLoad' JavaScript callback in 'inc/fancybox-2.php'. The 'this.href' value is directly concatenated into an HTML string without escaping, allowing an attacker to use entity-encoded double-quotes to break out of the data attribute and inject event handlers. This vulnerability requires contributor-level authentication or higher to exploit. Successful exploitation allows the execution of arbitrary web scripts in the context of a user's browser session when they interact with a malicious PDF link. A patch appears to be available in versions following 2.3.20.

Affected products

  • firelightwp Firelight Lightbox (Easy FancyBox) up to and including 2.3.20

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References