The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dfactory
Dfactory responsive Lightbox & Gallery Wordpress Wordpress wordpress |
|
| Vendors & Products |
Dfactory
Dfactory responsive Lightbox & Gallery Wordpress Wordpress wordpress |
Wed, 19 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services. | |
| Title | Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-19T05:45:14.684Z
Updated: 2025-11-19T20:32:11.323Z
Reserved: 2025-10-27T16:13:08.985Z
Link: CVE-2025-12359
Updated: 2025-11-19T20:32:07.771Z
Status : Awaiting Analysis
Published: 2025-11-19T06:15:45.890
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-12359
No data.