Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus fancybox-plus allows Reflected XSS.This issue affects Fancybox Plus: from n/a through <= 1.0.1.
Published: 2025-03-26
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fancybox Plus plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation flaw that can be triggered by user‑supplied data. When the plugin displays the reflected payload in the rendered page, a malicious script can execute in the browser of anyone who views the affected page, compromising confidentiality and potentially allowing data theft or session hijacking. This weakness is classified as CWE‑79.

Affected Systems

The vulnerability affects the puzich Fancybox Plus plugin for WordPress versions up to and including 1.0.1. No other vendors or product variants are listed in the CNA data.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that the exploitation rate is currently low. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form submission that the plugin processes without proper sanitization, leading to reflected script execution if a user interacts with the resulting page.

Generated by OpenCVE AI on May 2, 2026 at 03:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fancybox Plus to the latest version (≥ 1.0.2 if available).
  • If an upgrade is not possible, disable or completely remove the Fancybox Plus plugin from the WordPress installation.
  • Ensure that any user‑supplied content rendered by the plugin is properly escaped—use WordPress sanitization functions such as esc_html() or esc_js().

Generated by OpenCVE AI on May 2, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8137 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus allows Reflected XSS. This issue affects Fancybox Plus: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus allows Reflected XSS. This issue affects Fancybox Plus: from n/a through 1.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus fancybox-plus allows Reflected XSS.This issue affects Fancybox Plus: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 26 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus allows Reflected XSS. This issue affects Fancybox Plus: from n/a through 1.0.1.
Title WordPress Fancybox Plus plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:50.932Z

Reserved: 2025-03-11T08:10:05.094Z

Link: CVE-2025-28935

cve-icon Vulnrichment

Updated: 2025-03-26T14:54:56.823Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:16:17.727

Modified: 2026-04-23T15:26:38.100

Link: CVE-2025-28935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:30:16Z

Weaknesses