CVE 6.4 MEDIUM

Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library_CVE-2025-5092

6.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Description

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Basic Information

ID CVE-2025-5092
Source Wordfence
Published Nov 20, 2025 at 06:38

Affected Product

Vendor lightgalleryteam
Product LightGallery WP
Version *
Affected Versions lightgalleryteam LightGallery WP *
tplugins TP WooCommerce Product Gallery *
vowelweb Ibtana – WordPress Website Builder *
wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor *
wpsofts Portfolio, Gallery, Product Catalog – Grid KIT Portfolio *
famethemes OnePress *
galaxyweblinks Gallery with thumbnail slider *
wpkin Image Hover Effects Ultimate *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.