CVE-2025-15386
24.02.2026, 06:16
The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.