PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting
Affected versions: [*, 7.5); *; *; [*, 1.4.12); [*, 0.4.17); [*, 5.5); [*, 1.7.5); [*, 1.2.7.5)
Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected software, patched versions and attribution
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
Random image gallery with pretty photo zoom
Affected versions: [*, 7.5)
Patched versions: 7.5
mytreasures
Affected versions: *
Patched versions: Not supplied
wp-business-directory
Affected versions: *
Patched versions: Not supplied
Responsive Lightbox & Gallery
Affected versions: [*, 1.4.12)
Patched versions: 1.4.12
s2member Secure File Browser
Affected versions: [*, 0.4.17)
Patched versions: 0.4.17
TallyKit
Affected versions: [*, 5.5)
Patched versions: 5.5
WP Video Lightbox
Affected versions: [*, 1.7.5)
Patched versions: 1.7.5
Alpine Photo Tile for Instagram
Affected versions: [*, 1.2.7.5)
Patched versions: 1.2.7.5
eHive Account Details
Affected versions: [*, 2.1.3)
Patched versions: 2.1.3
WP Easy Gallery – WordPress Gallery Plugin
Affected versions: [*, 4.1.1)
Patched versions: 4.1.1
fancyflickr
Affected versions: *
Patched versions: Not supplied
Gallery Bank – WordPress Photo Gallery Plugin
Affected versions: [*, 3.0.229)
Patched versions: 3.0.229
ReFlex Gallery » WordPress Photo Gallery
Affected versions: [*, 3.1.5)
Patched versions: 3.1.5
matrix-image-gallery
Affected versions: *
Patched versions: Not supplied
Apizee Contact – Live Chat Plugin
Affected versions: [*, 1.1)
Patched versions: 1.1
dp-maintenance-mode-lite
Affected versions: *
Patched versions: Not supplied
WP Portfolio Gallery
Affected versions: [*, 1.2.0)
Patched versions: 1.2.0
ticket-manager
Affected versions: *
Patched versions: Not supplied
lb-tube-video
Affected versions: *
Patched versions: Not supplied
eHive Object Details
Affected versions: [*, 2.1.7)
Patched versions: 2.1.7
Onclick show popup
Affected versions: [*, 6.6)
Patched versions: 6.6
jcwp youtube channel embed
Affected versions: [*, 2.0.0)
Patched versions: 2.0.0
FoxyShop
Affected versions: [*, 4.6.1)
Patched versions: 4.6.1
Contact Bank – Contact Form Builder for WordPress
Affected versions: [*, 2.0.227)
Patched versions: 2.0.227
Image Slider
Affected versions: [*, 1.1.7)
Patched versions: 1.1.7
Images Lazyload and Slideshow
Affected versions: [*, 3.3)
Patched versions: 3.3
WPPizza – A Restaurant Plugin
Affected versions: [*, 2.11.8.18)
Patched versions: 2.11.8.18
responsive-category-slider
Affected versions: *
Patched versions: Not supplied
MyBlogU
Affected versions: [*, 0.0.8)
Patched versions: 0.0.8
TreXanh Property
Affected versions: *-0.1
Patched versions: 0.2
embedplus-for-wordpress
Affected versions: [*, 5.4)
Patched versions: 5.4
webrotate-360-product-viewer
Affected versions: [*, 2.5.2)
Patched versions: 2.5.2
wp-instagram-bank
Affected versions: *
Patched versions: Not supplied
mklasens-photobox
Affected versions: *
Patched versions: Not supplied
Researcher credit: Anant Shrivastava (anantshri), PeruCrack
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
This record contains material that is subject to copyright
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
- Published
- August 1, 2014
- CVSS
- 6.1