T
he Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.
References
Configurations
No configuration.
History
24 Feb 2026, 17:29
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
24 Feb 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 06:16
Updated : 2026-02-24 17:29
NVD link : CVE-2025-15386
Mitre link : CVE-2025-15386
CVE.ORG link : CVE-2025-15386
JSON object : View
Products Affected
No product.
CWE
No CWE.