Home

Description

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.

PUBLISHED Reserved 2025-04-15 | Published 2025-05-12 | Updated 2025-05-12 | Assigner WPScan

Problem types

CWE-79 Cross-Site Scripting (XSS)

Product status

Default status
unaffected

Any version before 2.3.4
affected

Credits

Pierre Rudloff finder

WPScan coordinator

References

wpscan.com/...rability/37fb7f3b-1766-4c2c-9b78-f77f15a04476/ exploit vdb-entry technical-description

cve.org (CVE-2025-3649)

nvd.nist.gov (CVE-2025-3649)

Download JSON