Stored Cross-Site Scripting Vulnerability in Responsive Lightbox & Gallery Plugin for WordPress
CVE-2026-103897

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-103897?

The Responsive Lightbox & Gallery plugin for WordPress contains a vulnerability that allows authenticated attackers with editor-level access and higher to exploit stored cross-site scripting (XSS) through the 'comment' parameter. This occurs due to insufficient input sanitization and output escaping, enabling the injection of arbitrary web scripts into pages. When the 'Comments' lightbox setting is enabled, which is turned off by default, moderated comments can be manipulated to include injected scripts. A user accessing the affected image may inadvertently execute these scripts upon interaction with the lightbox, posing significant security risks to site visitors.

Affected Version(s)

Responsive Lightbox & Gallery 0 <= 2.7.9

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
.