Cross-Site Scripting Vulnerability in Noor Alam WP Fancybox by WordPress
CVE-2025-26591
6.5MEDIUM
What is CVE-2025-26591?
A Cross-Site Scripting (XSS) vulnerability in Noor Alam's WP Fancybox allows attackers to inject malicious scripts into web pages. This issue compromises the integrity of the application and can lead to stored XSS attacks, affecting users who visit the manipulated page. Affected versions range from n/a to 1.0.4, making it crucial for site administrators to take immediate action to mitigate potential risks.
Affected Version(s)
WP fancybox <= 1.0.4