CVE-2024-5425

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THE original Lightbox script (v2).
GitHubGitHub
6.38K
<p>LightPress Lightbox is a popular, very lightweight lightbox plugin for WordPress. It is active 40,000 websites. After activation, settings will appear under &#8216;Lightbox&#8217; on your website&#8217;s main admin menu, and images and galleries will open in a nice lightbox.</p> <p>To make images open in the lightbox, you need to set images to &#8220;Link To:&#8221; media file. For image blocks, this setting is on the toolbar at the top of the block. For galleries, this setting is on the sidebar by other block options.</p> <p><strong>LIGHTBOX DEMOS</strong></p> <p><strong><a href="https://lightpress.io/free-lightbox/" rel="nofollow ugc">Free Lightbox Demo</a></strong><br /> <strong><a href="https://lightpress.io/pro-lightbox/" rel="nofollow ugc">Pro Lightbox Demo &#8211; Light Theme</a></strong><br /> <strong><a href="https://lightpress.io/pro-lightbox-dark/" rel="nofollow ugc">Pro Lightbox Demo &#8211; Dark Theme</a></strong></p> <p><strong>FREE LIGHTBOX FEATURES</strong><br /> &#8211; Automatic detection of images and galleries<br /> &#8211; Customize colors of lightbox and navigation<br /> &#8211; Classic and modern navigation styles<br /> &#8211; Option to show info bar<br /> &#8211; Option to show title or alt text<br /> &#8211; Option to show download button<br /> &#8211; Slideshow options<br /> &#8211; Keyboard navigation<br /> &#8211; And more!</p> <p>Links:<br /> -&gt; <strong><a href="https://lightpress.io/free-lightbox/" rel="nofollow ugc">Demos</a></strong><br /> -&gt; <strong><a href="https://lightpress.io/free-lightbox-documentation/" rel="nofollow ugc">Docs</a></strong><br /> -&gt; <strong><a href="https://wordpress.org/support/plugin/wp-jquery-lightbox/" rel="ugc">Free Support</a></strong></p> <p><strong>PRO LIGHTBOX FEATURES</strong></p> <p>LightPress Pro is a premium extension for this lightbox plugin that offers:<br /> &#8211; Priority support via email directly from devs<br /> &#8211; <em>Powerful, Modern Pro Lighbox</em><br /> &#8211; Beautiful, modern full-browser and full-screen ligthbox<br /> &#8211; Dozens of customizations options<br /> &#8211; Thumbnails within the lightbox<br /> &#8211; Toolbar with controls for thumbnails, zoom, slideshow, and more<br /> &#8211; Open videos (Youtube, Vimeo, self-hosted)<br /> &#8211; Opens PDF files<br /> &#8211; Opens content from external web pages<br /> &#8211; Create easy modals and popup boxes<br /> &#8211; Open image maps<br /> &#8211; Flawless on mobile devices<br /> &#8211; Hyper fast performance</p> <p>-&gt; <strong><a href="https://lightpress.io/pro-lightbox/" rel="nofollow ugc">VIEW PRO LIGHTBOX DEMOS</a></strong><br /> -&gt; <strong><a href="https://lightpress.io/contact/" rel="nofollow ugc">GET PRO SUPPORT</a></strong></p> <p><strong>Background and Thanks</strong></p> <p>Special thanks to <a href="http://www.ulfbenjaminsson.com" rel="nofollow ugc">Ulf Benjaminsson</a>, who created the original WP JQuery Lightbox plugin and maintained it for many years.</p> <h3>Additional Info</h3> <p>Copyright (C) 2010-2023 Ulf Benjaminsson.<br /> Copyright (C) 2023-Present LightPress LLC.</p> <p>This program is free software; you can redistribute it and/or modify<br /> it under the terms of the GNU General Public License as published by<br /> the Free Software Foundation; either version 2 of the License, or<br /> (at your option) any later version.</p> <p>This program is distributed in the hope that it will be useful,<br /> but WITHOUT ANY WARRANTY; without even the implied warranty of<br /> MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the<br /> GNU General Public License for more details.</p> <p>You should have received a copy of the GNU General Public License<br /> along with this program; if not, write to the Free Software<br /> Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA</p>
WordPress Plugin DirectoryWordPress Plugin Directory
909K