Impact
The Lightbox with PhotoSwipe WordPress plugin before version 5.9.0 does not sanitize the data-lbwps-caption attribute before rendering it into the image lightbox caption. This oversight allows users with author or higher roles, who do not have the unfiltered_html capability, to store malicious JavaScript that is executed in the browser when a visitor or administrator opens a lightbox. The flaw enables arbitrary script execution in the context of the site, potentially leading to cookie theft, session hijacking, content injection, or defacement. The underlying weakness aligns with improper neutralization of input during web page generation.
Affected Systems
All WordPress installations that use the Lightbox with PhotoSwipe plugin with a version earlier than 5.9.0 are affected. The vulnerability propagates to any site using the plugin, regardless of size, as long as an author‑level user or higher has access to the plugin’s configuration interface.
Risk and Exploitability
While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the flaw presents a high‑impact stored XSS risk. Attackers can exploit the vulnerability by creating or editing a link caption through the plugin’s normal admin interface, a capability that requires only author‑level access. Once an end‑user or site administrator opens the lightbox, the injected JavaScript runs, giving the attacker the same privileges as the site’s frontend environment. In the absence of a CVSS score, the potential for widespread impact remains significant, especially on sites with public visitors.
OpenCVE Enrichment