Description
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the plugin's 'Comments' lightbox setting to be enabled (disabled by default), a moderator to approve the injected comment, and a site visitor to click the affected image to open the lightbox.
Published: 2026-10-10
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via comment titles exploitable by authenticated editors
Action: Update Now
AI Analysis

Impact

The plugin accepted unfiltered comment content in the ‘title’ attribute of comments, allowing an attacker with editor or higher rights to embed malicious JavaScript. When the comment is approved, the payload is stored and rendered each time a visitor opens an affected image in the lightbox. This stored XSS can lead to data theft, session hijacking, or defacement on the victim's browser. The impact is limited to users who view the injected image, but the compromise can be widespread if the site has many visitors.

Affected Systems

All installations of dfactory Responsive Lightbox & Gallery for WordPress up to and including version 2.7.9 are affected. The vulnerability applies to every site that has installed this plugin and the Comments lightbox setting enabled.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.4, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers need authenticated editor‑level access, the Comments lightbox setting must be turned on, and a moderator must approve the comment before exploitation is possible. Once these conditions are met, any visitor who opens the image will execute the attacker’s script.

Generated by OpenCVE AI on October 10, 2026 at 08:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version that patches the comment title sanitization flaw. If a newer version is not available, immediately stop using Responsive Lightbox & Gallery.
  • Disable the “Comments” lightbox setting so that no comment titles are rendered in the lightbox until the plugin is fixed. This stops the stored payload from being served to visitors.
  • Restrict editor or higher privileges to a minimum necessary set of users, and audit comment approvals closely to prevent malicious content from being approved.

Generated by OpenCVE AI on October 10, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the plugin's 'Comments' lightbox setting to be enabled (disabled by default), a moderator to approve the injected comment, and a site visitor to click the affected image to open the lightbox.
Title Responsive Lightbox & Gallery <= 2.7.9 - Authenticated (Editor+) Stored Cross-Site Scripting via Comment Content 'title' Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:11.397Z

Reserved: 2026-10-01T13:51:02.919Z

Link: CVE-2026-103897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.257

Modified: 2026-10-10T07:16:40.257

Link: CVE-2026-103897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')