Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ibtana Visual Editor Plugin | — | Update ibtana-visual-editor plugin to version 1.2.5.2, or a newer patched version | Nov 28, 2025 | Nov 19, 2025 |
| Portfolio Wp Plugin | — | Update portfolio-wp plugin to version 2.2.2, or a newer patched version | Nov 28, 2025 | Nov 19, 2025 |
| Royal Elementor Addons Plugin | — | Update royal-elementor-addons plugin to version 1.7.1032, or a newer patched version | Nov 28, 2025 | Nov 19, 2025 |
| Tp Woocommerce Product Gallery Plugin | — | Update tp-woocommerce-product-gallery plugin to version 2.0.0, or a newer patched version | Nov 28, 2025 | Nov 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub