CVE-2026-14833 PUBLISHED

Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute

Assigner: WPScan
Reserved: 06.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox.

Product Status

Vendor Unknown
Product Lightbox with PhotoSwipe
Versions Default: unaffected
  • affected from 0 to 5.9.0 (excl.)

Credits

  • Pierre Rudloff finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE