Логотип exploitDog
bind:CVE-2025-3597
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3597

Количество 2

Количество 2

nvd логотип

CVE-2025-3597

9 месяцев назад

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-hhrx-pjm2-54m9

9 месяцев назад

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3597

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

CVSS3: 5.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-hhrx-pjm2-54m9

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

CVSS3: 5.9
0%
Низкий
9 месяцев назад

Уязвимостей на страницу