Stored Cross-Site Scripting in Album and Image Gallery Plus Lightbox Plugin for WordPress
CVE-2025-13612
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-13612?
The Album and Image Gallery Plus Lightbox plugin exposes a serious vulnerability allowing authenticated users with contributor-level access or higher to exploit insufficient input sanitization and output escaping. By leveraging the plugin's aigpl-gallery-album shortcode, attackers can inject arbitrary web scripts into pages. These malicious scripts can execute whenever a user visits the affected page, potentially compromising user data and website integrity.
Affected Version(s)
Album and Image Gallery Plus Lightbox 0 <= 2.1.7