Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Easy Image Gallery Plugin | — | Update easy-image-gallery plugin to version 1.5.3, or a newer patched version | Dec 10, 2025 | Jul 2, 2025 |
| Woo 3d Viewer Plugin | — | Update woo-3d-viewer plugin to version 1.8.6.7, or a newer patched version | Jul 10, 2025 | Jul 2, 2025 |
| Wp Video Lightbox Plugin | — | Update wp-video-lightbox plugin to version 1.9.12, or a newer patched version | Jul 10, 2025 | Jul 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub