Medium 6.1
2025-06-03< 3.3.6
FancyBox for WordPress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting
Minimum safe version
3.3.6
Update to 3.3.6 or later to address 4 fixable vulnerabilities
FancyBox for WordPress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
CVE-2024-0662
CVE-2015-1494