Stored Cross-Site Scripting Vulnerability in Woostify Plugin for WordPress
CVE-2026-4805
6.4MEDIUM
What is CVE-2026-4805?
The Woostify plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to improper input sanitization and output escaping within the bundled Lity.js lightbox library. An attacker with Contributor-level access or higher can inject malicious scripts through user-controlled input in the href attribute, forming a jQuery HTML string without adequate protection. This vulnerability allows attackers to execute arbitrary scripts on pages viewed by users, potentially compromising the security of WordPress sites.
Affected Version(s)
Woostify 0 <= 2.5.0