Impact
The plugin accepted unfiltered comment content in the ‘title’ attribute of comments, allowing an attacker with editor or higher rights to embed malicious JavaScript. When the comment is approved, the payload is stored and rendered each time a visitor opens an affected image in the lightbox. This stored XSS can lead to data theft, session hijacking, or defacement on the victim's browser. The impact is limited to users who view the injected image, but the compromise can be widespread if the site has many visitors.
Affected Systems
All installations of dfactory Responsive Lightbox & Gallery for WordPress up to and including version 2.7.9 are affected. The vulnerability applies to every site that has installed this plugin and the Comments lightbox setting enabled.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.4, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers need authenticated editor‑level access, the Comments lightbox setting must be turned on, and a moderator must approve the comment before exploitation is possible. Once these conditions are met, any visitor who opens the image will execute the attacker’s script.
OpenCVE Enrichment