Sceawere
Vulnerability Detail
CVE-2026-103897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Responsive Lightbox Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 3h ago
- Vendor
- dfactory
- Product
- Responsive Lightbox & Gallery
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the plugin's 'Comments' lightbox setting to be enabled (disabled by default), a moderator to approve the injected comment, and a site visitor to click the affected image to open the lightbox.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-10-10T07:16:40.257Z",
"pubdate": "2026-10-10T07:16:40.257Z",
"executiveSummary": "The Responsive Lightbox & Gallery plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions 2.7.9 and earlier.\nThe vulnerability arises from improper handling of user-supplied input within the 'comment' parameter, allowing authenticated users with editor-level privileges or higher to inject malicious JavaScript payloads into the site's lightbox functionality.\nWhen rendered, these scripts execute within the context of a victim's browser session, potentially leading to unauthorized actions, session hijacking, or the defacement of the affected WordPress site.\nExploitation is contingent upon specific configuration requirements: the 'Comments' lightbox setting must be enabled, the malicious comment must be approved by a moderator, and a target user must trigger the lightbox interaction.\nGiven the requirement for authenticated access, the threat is primarily categorized as an escalation of privileges attack originating from compromised or malicious accounts with elevated permissions.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Responsive Lightbox & Gallery plugin to adequately sanitize user input and escape output within the 'comment' parameter processing logic. This flaw permits the injection of arbitrary HTML and JavaScript tags into the application's persistent storage.\nThe vulnerability resides within the plugin's comment handling module, which integrates directly with the lightbox display mechanism. When the 'Comments' lightbox feature is active, the plugin retrieves comment data from the database and renders it directly into the DOM of the lightbox modal without performing sufficient context-aware output encoding.\nThe attack flow proceeds as follows: First, an authenticated attacker with editor privileges submits a comment containing a malicious XSS payload via the standard WordPress comment submission process. Second, the payload is persisted in the database associated with the target image or gallery. Third, an administrative moderator must approve the comment, effectively moving the payload from a pending state to a public-facing display state. Fourth, an unsuspecting end-user interacts with the affected image, triggering the lightbox modal. Finally, the browser parses and executes the injected JavaScript code within the context of the lightbox window, potentially enabling the attacker to steal cookies, perform actions on behalf of the victim, or redirect the user to malicious external domains.\nThe lack of server-side sanitization at the input stage combined with the absence of secure client-side output encoding creates a classic Stored XSS vector. Because the payload is permanently stored within the database, the script is executed every time a victim opens the specific image lightbox. This bypasses typical reflective protections, as the attack is persistent and requires no specific URL manipulation by the attacker beyond initial comment submission. The impact is significant for authenticated administrative users, as session tokens or administrative credentials could be harvested during the execution of the injected script, leading to full site compromise if administrative sessions are targeted."
}