CVE-2025-3745

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:syedbalkhi:wp_lightbox_2:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-06-30 06:15

Updated : 2025-07-01 16:38


NVD link : CVE-2025-3745

Mitre link : CVE-2025-3745

CVE.ORG link : CVE-2025-3745


JSON object : View

Products Affected

syedbalkhi

  • wp_lightbox_2
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')