Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

7 vulnerability records

MediumCVE-2026-6454

Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute

Firelight Lightbox: Currently marked unpatched

Affected versions: *-2.3.20

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-concatenated directly into an HTML string without escaping, allowing a stored href containing entity-encoded double-quotes to break out of the data attribute and inject arbitrary event handlers into the DOM. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that execute whenever a user clicks the malicious PDF link.

Firelight Lightbox

Affected versions: *-2.3.20

Patched versions: 2.3.21

Researcher credit: Quốc Huy (jtwings)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 23, 2026
CVSS
6.4
MediumCVE-2025-52707

Firelight Lightbox <= 2.3.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

Firelight Lightbox: Currently marked unpatched

Affected versions: *-2.3.16

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Firelight Lightbox

Affected versions: *-2.3.16

Patched versions: 2.3.17

Researcher credit: Prissy

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 19, 2025
CVSS
6.4
MediumCVE-2025-5035

Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

Firelight Lightbox: Currently marked unpatched

Affected versions: *-2.3.15

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.15 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Firelight Lightbox

Affected versions: *-2.3.15

Patched versions: 2.3.16

Researcher credit: Pierre Rudloff

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 6, 2025
CVSS
6.4
MediumCVE-2025-3597

Firelight Lightbox <= 2.3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

Firelight Lightbox: Currently marked unpatched

Affected versions: *-2.3.14

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to, and including, 2.3.14 due to insufficient input sanitization and output escaping when the jQuery Metadata library is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Firelight Lightbox

Affected versions: *-2.3.14

Patched versions: 2.3.15

Researcher credit: Pierre Rudloff

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 21, 2025
CVSS
6.4
MediumCVE-2024-5020

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

Responsive Lightbox & Gallery: Currently marked unpatchedWPC Smart Quick View for WooCommerce: Currently marked unpatchedAccordion Slider: Currently marked unpatchedFV Flowplayer Video Player: Currently marked unpatchedEnvira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More: Currently marked unpatchedColibri Page Builder: Currently marked unpatchedGallery by Visual Portfolio: Currently marked unpatchedGetwid – Gutenberg Blocks: Currently marked unpatchedFirelight Lightbox: Currently marked unpatchedNexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder: Currently marked unpatchedFancyBox for WordPress: Currently marked unpatchedCarousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel: Currently marked unpatchedForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Currently marked unpatchedPhoto Gallery, Sliders, Proofing and Themes – NextGEN Gallery: Currently marked unpatchedEasy Social Feed Premium: Currently marked unpatched

Affected versions: *-2.4.8; *-4.1.1; *-1.9.12; *-7.5.47.7212; *-1.8.15; *-1.0.286; *-3.3.9; *-2.0.11

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Responsive Lightbox & Gallery

Affected versions: *-2.4.8

Patched versions: 2.4.9

WPC Smart Quick View for WooCommerce

Affected versions: *-4.1.1

Patched versions: 4.1.2

Accordion Slider

Affected versions: *-1.9.12

Patched versions: 1.9.13

FV Flowplayer Video Player

Affected versions: *-7.5.47.7212

Patched versions: 7.5.48.7212

Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

Affected versions: *-1.8.15

Patched versions: 1.8.16

Colibri Page Builder

Affected versions: *-1.0.286

Patched versions: 1.0.288

Gallery by Visual Portfolio

Affected versions: *-3.3.9

Patched versions: 3.3.10

Getwid – Gutenberg Blocks

Affected versions: *-2.0.11

Patched versions: 2.0.12

Firelight Lightbox

Affected versions: *-2.3.3

Patched versions: 2.3.4

Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Affected versions: *-4.3.1

Patched versions: 4.3.2

FancyBox for WordPress

Affected versions: *-3.3.4

Patched versions: 3.3.5

Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel

Affected versions: *-2.6.8

Patched versions: 2.6.9

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Affected versions: *-1.15.27

Patched versions: 1.15.28

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Affected versions: *-3.59.4

Patched versions: 3.59.5

Easy Social Feed Premium

Affected versions: *-6.6.2

Patched versions: Not supplied

Researcher credit: Webbernaut

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 3, 2024
CVSS
6.4
MediumCVE-2024-50460

Firelight Lightbox <= 2.3.3 - Authenticated (Author+) Stored Cross-Site Scripting

Firelight Lightbox: Currently marked unpatched

Affected versions: *-2.3.3

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Firelight Lightbox

Affected versions: *-2.3.3

Patched versions: 2.3.4

Researcher credit: Robert DeVore

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 24, 2024
CVSS
6.4
MediumCVE-2019-16524

Easy Fancybox <= 1.8.17 - Authenticated Stored Cross-Site Scripting

Firelight Lightbox: Currently marked unpatched

Affected versions: *-1.8.17

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

Firelight Lightbox

Affected versions: *-1.8.17

Patched versions: 1.8.18

Researcher credit: Jakob Hagl

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 25, 2019
CVSS
5.5

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.