The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
History

Thu, 05 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Firelightwp
Firelightwp firelight Lightbox
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:firelightwp:firelight_lightbox:*:*:*:*:*:wordpress:*:*
Vendors & Products Firelightwp
Firelightwp firelight Lightbox

Mon, 12 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Title Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-12T06:00:02.515Z

Updated: 2025-05-12T17:31:53.398Z

Reserved: 2025-04-14T14:51:43.622Z

Link: CVE-2025-3597

cve-icon Vulnrichment

Updated: 2025-05-12T17:23:26.801Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-12T06:15:39.030

Modified: 2025-06-05T14:27:53.477

Link: CVE-2025-3597

cve-icon Redhat

No data.