CVE-2025-3742: Responsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSS
Published May 15, 2025
·Updated
The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
2 affected components
WordPress Responsive Lightbox & Gallery<2.5.1
dFactory Responsive Lightbox Wordpress<2.5.1
Event History
May 15, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-3742?
CVE-2025-3742 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2025-3742?
To fix CVE-2025-3742, update the Responsive Lightbox & Gallery plugin to version 2.5.1 or later.
3
Who is affected by CVE-2025-3742?
Users with the contributor role and above in WordPress are affected by CVE-2025-3742.
4
What type of vulnerability is CVE-2025-3742?
CVE-2025-3742 is a Stored Cross-Site Scripting vulnerability.
5
When was CVE-2025-3742 published?
CVE-2025-3742 was published in 2025.