ZeroHour

CVE-2025-3745

PoC
CVSS 3.1
6.3 medium
EPSS
<1%p12
Published
()
Modified
Description

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

Vendors
syedbalkhi
Products
wp lightbox 2
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.