CVE-2025-15386

T

he Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

Configurations

No configuration.

History

24 Feb 2026, 17:29

Type Values Removed Values Added
Summary
  • (es) El plugin de WordPress Responsive Lightbox & Gallery anterior a 2.6.1 es vulnerable a un ataque de XSS Almacenado No Autenticado debido a reglas de reemplazo de expresiones regulares defectuosas que pueden ser explotadas al publicar un comentario con un enlace malicioso cuando la lightbox para comentarios está habilitada y luego aprobada.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

24 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 06:16

Updated : 2026-02-24 17:29


NVD link : CVE-2025-15386

Mitre link : CVE-2025-15386

CVE.ORG link : CVE-2025-15386


JSON object : View

Products Affected

No product.

CWE

No CWE.