Stored Cross-Site Scripting Vulnerability in WordPress Plugins and Themes Using lightGallery
CVE-2025-5092
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 20 November 2025
What is CVE-2025-5092?
Multiple WordPress plugins and themes employing the lightGallery library are susceptible to Stored Cross-Site Scripting due to inadequate sanitization of user input and improper escaping of output. Authenticated attackers with Contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts, which execute whenever users access a compromised page. Users should take immediate precautions to secure their installations by reviewing and updating affected plugins or themes to mitigate potential attacks.
Affected Version(s)
Gallery with thumbnail slider * <= 7.8
Ibtana – WordPress Website Builder * <= 1.2.5.1
Image Hover Effects Ultimate * <= 9.10.5