N/A
2026-04-07< 2.3.5
LightPress Lightbox <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'group' Shortcode Attribute
Minimum safe version
2.3.5
Update to 2.3.5 or later to address 3 fixable vulnerabilities
LightPress Lightbox <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'group' Shortcode Attribute
WordPress WP jQuery Lightbox Plugin < 2.3.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5425