ZeroHour

CVE-2025-9710

CVSS 3.1
6.3 medium
EPSS
<1%p12
Published
()
Modified
Description

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.

Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.