Stored Cross-Site Scripting Vulnerability in Responsive Lightbox & Gallery Plugin for WordPress
CVE-2026-103897
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103897?
The Responsive Lightbox & Gallery plugin for WordPress contains a vulnerability that allows authenticated attackers with editor-level access and higher to exploit stored cross-site scripting (XSS) through the 'comment' parameter. This occurs due to insufficient input sanitization and output escaping, enabling the injection of arbitrary web scripts into pages. When the 'Comments' lightbox setting is enabled, which is turned off by default, moderated comments can be manipulated to include injected scripts. A user accessing the affected image may inadvertently execute these scripts upon interaction with the lightbox, posing significant security risks to site visitors.
Affected Version(s)
Responsive Lightbox & Gallery 0 <= 2.7.9