ZeroHour

CVE-2025-3597

PoC
CVSS 3.1
5.9 medium
EPSS
<1%p23
Published
()
Modified
Description

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

Vendors
firelightwp
Products
firelight lightbox
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.