CVE-2026-28103: WordPress LBG Zoominoutslider plugin <= 5.4.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 5, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbgzoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.
Affected Software
2 affected components
LambertGroup LBG Zoominoutslider<=5.4.5
wordpress/lbg_zoominoutslider<=5.4.5
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28103?
CVE-2026-28103 has a high severity rating due to its potential to allow reflected cross-site scripting attacks.
2
How do I fix CVE-2026-28103?
To fix CVE-2026-28103, update the LBG Zoominoutslider plugin to the latest version beyond 5.4.5.
3
What type of vulnerability is CVE-2026-28103?
CVE-2026-28103 is a reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-28103?
CVE-2026-28103 affects users of the LBG Zoominoutslider plugin version 5.4.5 and earlier.
5
What can attackers do with CVE-2026-28103?
Attackers exploiting CVE-2026-28103 can execute arbitrary scripts in the context of the affected user's session.