Impact
The vulnerability is an improper neutralization of input during web page generation that allows a reflected cross‑site scripting (XSS) attack in the Your Lightbox plugin. This flaw is classified as CWE‑79. Based on the description, it is inferred that an attacker could inject arbitrary JavaScript that executes in the victim’s browser, potentially leading to cookie theft, defacement, or other malicious actions.
Affected Systems
Reuven Karasik’s WordPress plugin Your Lightbox, versions from the initial release up to and including 1.0, is affected by this flaw. No higher versions were listed as vulnerable in the current advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA KEV. The attack vector is inferred as reflected via user input that the plugin echoes back; an attacker could craft a malicious URL or form input to deliver the payload without requiring authentication.
OpenCVE Enrichment
EUVD