The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved. | |
| Title | Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-02-24T06:00:07.864Z
Reserved: 2025-12-31T07:28:37.400Z
Link: CVE-2025-15386
No data.
Status : Received
Published: 2026-02-24T06:16:34.583
Modified: 2026-02-24T06:16:34.583
Link: CVE-2025-15386
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.