The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Lightpress
Lightpress lightbox
Weaknesses CWE-79
CPEs cpe:2.3:a:lightpress:lightbox:*:*:*:*:*:wordpress:*:*
Vendors & Products Lightpress
Lightpress lightbox

Mon, 12 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 May 2025 06:15:00 +0000

Type Values Removed Values Added
Description The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
Title LightPress Lightbox < 2.3.4 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-05-12T17:03:04.531Z

Reserved: 2025-04-15T14:42:22.990Z

Link: CVE-2025-3649

cve-icon Vulnrichment

Updated: 2025-05-12T17:02:33.168Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-12T06:15:40.270

Modified: 2025-06-05T14:27:28.437

Link: CVE-2025-3649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.