CVE-2025-5093: Responsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSS
The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5093?
CVE-2025-5093 is considered a medium severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-5093?
To fix CVE-2025-5093, update the Responsive Lightbox & Gallery WordPress plugin to version 2.5.2 or later.
Who is affected by CVE-2025-5093?
Users with contributor role and above in WordPress are affected by CVE-2025-5093 due to insufficient validation and escaping of title attributes.
What kind of attack can CVE-2025-5093 facilitate?
CVE-2025-5093 can facilitate Stored Cross-Site Scripting (XSS) attacks that may compromise user data.
What software versions are impacted by CVE-2025-5093?
CVE-2025-5093 affects versions of the Responsive Lightbox & Gallery plugin before 2.5.2.