CVE-2025-15386 PUBLISHED

Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

Assigner: WPScan
Reserved: 31.12.2025 Published: 24.02.2026 Updated: 24.02.2026

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

Product Status

Vendor Unknown
Product Responsive Lightbox & Gallery
Versions Default: unaffected
  • affected from 1.7.0 to 2.6.1 (excl.)

Credits

  • Matthew Rollings finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE