The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS
History

Thu, 05 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Colorlib
Colorlib fancybox
Weaknesses CWE-79
CPEs cpe:2.3:a:colorlib:fancybox:*:*:*:*:*:wordpress:*:*
Vendors & Products Colorlib
Colorlib fancybox

Tue, 03 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS
Title FancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-06-03T06:00:17.231Z

Updated: 2025-06-03T15:28:29.716Z

Reserved: 2025-04-15T19:54:17.214Z

Link: CVE-2025-3662

cve-icon Vulnrichment

Updated: 2025-06-03T15:28:23.746Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-03T06:15:27.873

Modified: 2025-06-05T14:09:58.017

Link: CVE-2025-3662

cve-icon Redhat

No data.