Medium 5.4
2025-06-27< 2.3.16
Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
2.3.17
Update to 2.3.17 or later to address 6 fixable vulnerabilities
Firelight Lightbox <= 2.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-52707
Firelight Lightbox <= 2.3.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
CVE-2024-50460
CVE-2019-16524