CVE-2025-9710

⚪ Do wiadomości

Błąd w wtyczce Responsive Lightbox & Gallery umożliwia ataki XSS przez nieautoryzowanych użytkowników.

CVSS
6.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-06 06:15:37 UTC
Ostatnia modyfikacja (NVD)2026-10-09 10:10:00 UTC
Referencje