CVE Database
/

CVE-2025-15386

Back to search

CVE-2025-15386

Published: Feb 24, 2026

Modified: Feb 24, 2026

PUBLISHED

Description

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

VendorProductVersions

Unknown

Responsive Lightbox & Gallery

affected
1.7.0 - < 2.6.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now