The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Firelightwp
Firelightwp firelight Lightbox |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:firelightwp:firelight_lightbox:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Firelightwp
Firelightwp firelight Lightbox |
Mon, 12 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 12 May 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well. | |
Title | Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-12T06:00:02.515Z
Updated: 2025-05-12T17:31:53.398Z
Reserved: 2025-04-14T14:51:43.622Z
Link: CVE-2025-3597

Updated: 2025-05-12T17:23:26.801Z

Status : Analyzed
Published: 2025-05-12T06:15:39.030
Modified: 2025-06-05T14:27:53.477
Link: CVE-2025-3597

No data.