The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/1b50f686-c2e0-4963-95c8-b27137dcc059/ | Exploit Third Party Advisory |
Configurations
History
01 Jul 2025, 16:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:syedbalkhi:wp_lightbox_2:*:*:*:*:*:wordpress:*:* | |
First Time |
Syedbalkhi
Syedbalkhi wp Lightbox 2 |
|
CWE | CWE-79 | |
References | () https://wpscan.com/vulnerability/1b50f686-c2e0-4963-95c8-b27137dcc059/ - Exploit, Third Party Advisory |
30 Jun 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-30 06:15
Updated : 2025-07-01 16:38
NVD link : CVE-2025-3745
Mitre link : CVE-2025-3745
JSON object : View
Products Affected
syedbalkhi
- wp_lightbox_2
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')