Cross-site Scripting Vulnerability in Firelight Lightbox by FirelightWP
CVE-2024-50460

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 October 2024

What is CVE-2024-50460?

The Firelight Lightbox plugin for WordPress presents a vulnerability due to improper neutralization of input during web page generation, leading to stored Cross-site Scripting (XSS) issues. This vulnerability can allow an attacker to inject malicious scripts into web pages, potentially compromising the security of users and their data. Affected versions include any prior to 2.3.3, making it essential for users to update immediately to mitigate the risks associated with this security flaw.

Affected Version(s)

Firelight Lightbox 0 <= 2.3.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.