CVE-2025-3745: WP Lightbox 2 < 3.0.6.8 - Unauthenticated Stored XSS
Published Jun 30, 2025
·Updated
The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.
Affected Software
2 affected components
WP Lightbox 2<3.0.6.8
Syedbalkhi Wp Lightbox 2 Wordpress<3.0.6.8
Event History
Jun 30, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3745?
CVE-2025-3745 is considered a high severity vulnerability due to its potential for allowing XSS attacks.
2
How do I fix CVE-2025-3745?
To fix CVE-2025-3745, update the WP Lightbox 2 plugin to version 3.0.6.8 or higher.
3
What type of vulnerability is CVE-2025-3745?
CVE-2025-3745 is an XSS (Cross-Site Scripting) vulnerability due to insufficient input sanitization.
4
In which versions is CVE-2025-3745 present?
CVE-2025-3745 affects WP Lightbox 2 versions prior to 3.0.6.8.
5
Who is affected by CVE-2025-3745?
Users of the WP Lightbox 2 WordPress plugin before version 3.0.6.8 are affected by CVE-2025-3745.