CVE-2025-3662: FancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS
The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3662?
CVE-2025-3662 has been classified with a critical severity due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-3662?
To fix CVE-2025-3662, update the FancyBox for WordPress plugin to version 3.3.6 or later.
What are the potential impacts of CVE-2025-3662?
The impact of CVE-2025-3662 includes the possibility of executing malicious scripts in the user's browser, leading to unauthorized actions and data theft.
Who is affected by CVE-2025-3662?
Users of the FancyBox for WordPress plugin versions prior to 3.3.6 are affected by CVE-2025-3662.
Is CVE-2025-3662 an authenticated vulnerability?
CVE-2025-3662 is an unauthenticated vulnerability, which means it can be exploited without needing to log in.