Server-Side Request Forgery Vulnerability in Responsive Lightbox & Gallery Plugin by WordPress
CVE-2026-2479
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 February 2026
What is CVE-2026-2479?
A vulnerability exists in the Responsive Lightbox & Gallery plugin for WordPress, allowing authenticated attackers with Author-level permissions or higher to exploit server-side request forgery. This security flaw arises from the plugin's improper hostname validation in the ajax_upload_image() function. By using strpos() for substring checks rather than a strict host comparison, attackers can potentially manipulate web requests to reach arbitrary locations. This exposes sensitive internal services to unauthorized queries and modifications, posing a significant risk to the integrity and confidentiality of the applications relying on those services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Responsive Lightbox & Gallery * <= 2.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved