CVE-2025-3745
30.06.2025, 06:15
The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.
Vendor | Product | Version |
---|---|---|
syedbalkhi | wp_lightbox_2 | 𝑥 < 3.0.6.8 |
𝑥
= Vulnerable software versions