CVE-2024-13362
Lightbox & Modal Popup WordPress Plugin – FooBox
Minimum safe version
2.7.35
Update to 2.7.35 or later to address 16 fixable vulnerabilities
Lightbox & Modal Popup WordPress Plugin – FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2025-32139
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-5668
CVE-2024-3276
WordPress FooBox Image Lightbox Plugin < 2.7.27 is vulnerable to Cross Site Scripting (XSS)
FooBox Image Lightbox <= 1.0.4 - Cross-Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
Unauthorised AJAX Calls via Freemius
WordPress FooBox Image Lightbox Plugin <= 1.0.4 - Cross Site Scripting
WordPress FooBox Image Lightbox plugin <= 2.6.3 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress FooBox Image Lightbox plugin < 2.7.17 - Sensitive Information Disclosure vulnerability
WordPress FooBox Image Lightbox plugin < 2.7.17 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability