First published: Mon Dec 19 2022(Updated: )
The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Noorsplugin Responsive Lightbox2 | <1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3987 has a severity level that can be classified as high due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2022-3987, update the Responsive Lightbox2 plugin to version 1.0.4 or later.
Users with a role as low as contributor are at risk due to the vulnerability in CVE-2022-3987.
CVE-2022-3987 is identified as a Stored Cross-Site Scripting vulnerability.
Versions of Responsive Lightbox2 prior to 1.0.4 are vulnerable to CVE-2022-3987.