CVE-2024-6870
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.
<h4>Everything You Need in a WordPress Gallery Plugin</h4>
<p><a href="http://www.dfactory.co/products/responsive-lightbox/?utm_source=repo&utm_medium=link&utm_campaign=responsive-lightbox-plugin-free" rel="nofollow ugc">Responsive Lightbox and Gallery plugin</a> is a fully fledged WordPress gallery plugin with a powerful Drag & Drop Gallery Builder and Lightbox functionality that’s used daily by more than 100,000 active users and downloaded over 3 Million times.</p>
<p>The beauty of it is how easy it is for you to customize it and enhance its features thanks to <a href="?utm_source=repo&utm_medium=link&utm_campaign=responsive-lightbox-plugin-free" rel="nofollow ugc">free and premium extensions</a>.</p>
<h4>Why You Should Use Responsive Lightbox and Gallery Plugin</h4>
<h4>Easiest Gallery Builder</h4>
<p>Say goodbye to coding. With the built-in drag and drop Gallery builder, you will be able to create beautiful galleries, customize them, and add your preferred styles in minutes.</p>
<h4>Vast Customization Options</h4>
<p>Responsive Lightbox and Gallery plugin is packed with customization options per each gallery and lightbox style so you can tweak them to suit your website’s audience with just a few clicks.</p>
<h4>SEO-Friendly and Lightweight</h4>
<p>Responsive Lightbox and Gallery plugin is built keeping SEO and performance in mind, making it lightweight and fast when it comes to page load.</p>
<h4>Premium Extensions</h4>
<p>Looking to provide a premium experience to your visitors? Responsive Lightbox and Gallery plugin offers plenty of premium extensions to provide you with even more flexibility and customization options.</p>
<p>Need more reasons? <a href="http://www.dfactory.co/products/responsive-lightbox/?utm_source=repo&utm_medium=link&utm_campaign=responsive-lightbox-plugin-free" rel="nofollow ugc">Check them out here</a>!</p>
<h4>What some of our 100,000+ active users say about Responsive Lightbox and Gallery plugin</h4>
<ul>
<li>
<p>Amazing Gallery plugin!</p>
</li>
<li>
<p>Versatile and powerful for both sliders and galleries, many features and style options.</p>
</li>
<li>
<p>Really easy to use. Takes all the fiddling out of the process of creating a responsive gallery/lightbox.</p>
</li>
<li>
<p>I needed a lightbox plugin that works reliably. This marvelous plugin does the magic. Now I can spend more on my photography and less time customizing WordPress.</p>
</li>
<li>
<p>This plugin is quite flexible and effective. The functionality choices are broad and all quite easy to configure.</p>
</li>
</ul>
<h4>Need more galley options?</h4>
<p>Responsive Lightbox and Gallery plugin can be extended with our <a href="?utm_source=repo&utm_medium=link&utm_campaign=responsive-lightbox-plugin-free" rel="nofollow ugc">premium extensions</a>:</p>
<p><strong>Premium Extensions:</strong><br />
* <a href="http://www.dfactory.co/products/photo-art-bundle/" rel="nofollow ugc">Photo & Art bundle</a><br />
* <a href="http://www.dfactory.co/products/justified-gallery/" rel="nofollow ugc">Justified Gallery</a><br />
* <a href="http://www.dfactory.co/products/expander-gallery/" rel="nofollow ugc">Expander Gallery</a><br />
* <a href="http://www.dfactory.co/products/hidden-gallery/" rel="nofollow ugc">Hidden Gallery</a><br />
* <a href="http://www.dfactory.co/products/masonry-gallery-pro/" rel="nofollow ugc">Masonry Image Gallery</a><br />
* <a href="http://www.dfactory.co/products/slider-gallery/" rel="nofollow ugc">Slider Gallery</a><br />
* <a href="http://www.dfactory.co/products/lightcase-lightbox/" rel="nofollow ugc">Lightcase Lightbox</a><br />
* <a href="http://www.dfactory.co/products/photoswipe-lightbox/" rel="nofollow ugc">PhotoSwipe Lightbox</a><br />
* <a href="http://www.dfactory.co/products/lightgallery-lightbox/" rel="nofollow ugc">Lightgallery Lightbox</a><br />
* <a href="http://www.dfactory.co/products/strip-lightbox/" rel="nofollow ugc">Strip Lightbox</a><br />
* <a href="http://www.dfactory.co/products/fancybox-pro/" rel="nofollow ugc">Fancybox Pro</a><br />
* <a href="http://www.dfactory.co/products/lightbox-comments/" rel="nofollow ugc">Lightbox Comments</a></p>
<h4>Full Feature List</h4>
<ul>
<li>Powerful and easy-to-use gallery builder</li>
<li>3 beautiful gallery templates – Grid, Slider and Masonry</li>
<li>8 responsive lightbox scripts (SwipeBox, prettyPhoto, Nivo Lightbox, Image Lightbox, Tos “R” Us, Featherlight, Magnific Popup, GLightbox)</li>
<li>Create galleries from Media Library or Post attached images</li>
<li>Media Folders with a drag & drop interface</li>
<li>Access to millions of images through Remote Library</li>
<li>Option to import remote images to Media Library</li>
<li>Gutenberg editor compatibility</li>
<li>Iframe, Ajax, HTML5 and Inline lightbox content support</li>
<li>Advanced pagination, incl. AJAX and infinite scroll</li>
<li>Automatically add lightbox to WordPress image galleries</li>
<li>Automatically add lightbox to WordPress image links</li>
<li>Automatically add lightbox to WordPress video links (YouTube, Vimeo)</li>
<li>Automatically add lightbox to widgets content</li>
<li>Automatically add lightbox to WordPress comments content</li>
<li>WooCommerce product gallery support</li>
<li>Popular Page builders compatibility</li>
<li>Gallery widget</li>
<li>Single image widget</li>
<li>Option to display single post images as a gallery</li>
<li>Option to modify native WP gallery links image size</li>
<li>Option to set gallery images title from image title, caption, alt or description</li>
<li>Option to force lightbox for custom WP gallery replacements like Jetpack tiled galleries</li>
<li>Option to trigger lightbox on custom jquery events</li>
<li>Option to conditionally load scripts and styles only on pages that have images or galleries in post content</li>
<li>Highly customizable settings for each of the lightbox scripts</li>
<li>Highly customizable settings for each gallery</li>
<li>Multisite support</li>
<li>.pot file for translations included</li>
</ul>