The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.
References
Configurations
No configuration.
History
06 Oct 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
06 Oct 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-06 06:15
Updated : 2025-10-06 19:15
NVD link : CVE-2025-9710
Mitre link : CVE-2025-9710
CVE.ORG link : CVE-2025-9710
JSON object : View
Products Affected
No product.
CWE
No CWE.