Stored Cross-Site Scripting Vulnerability in WordPress Plugins and Themes Using lightGallery
CVE-2025-5092
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 20 November 2025
What is CVE-2025-5092?
Multiple WordPress plugins and themes employing the lightGallery library are susceptible to Stored Cross-Site Scripting due to inadequate sanitization of user input and improper escaping of output. Authenticated attackers with Contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts, which execute whenever users access a compromised page. Users should take immediate precautions to secure their installations by reviewing and updating affected plugins or themes to mitigate potential attacks.
Affected Version(s)
Gallery with thumbnail slider * <= 7.8
Ibtana β WordPress Website Builder * <= 1.2.5.1
Image Hover Effects Ultimate * <= 9.10.5
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Craig Smith