CVE-2025-9710
⚪ Do wiadomości
Błąd w wtyczce Responsive Lightbox & Gallery umożliwia ataki XSS przez nieautoryzowanych użytkowników.
CVSS
6.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-06 06:15:37 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 10:10:00 UTC |