cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foreasy-fancybox easy-fancybox

Direction: descending
May 14, 2025

Easy FancyBox – WordPress Lightbox Plugin # CVE-2025-3597

CVE, Research URL

CVE-2025-3597

Date
May 12, 2025
Research Description
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Affected versions
Min -, max -.
Status
vulnerable
Dec 06, 2024

Easy FancyBox – WordPress Lightbox Plugin # CVE-2024-5020

CVE, Research URL

CVE-2024-5020

Date
Dec 04, 2024
Research Description
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Oct 27, 2024

Easy FancyBox – WordPress Lightbox Plugin # CVE-2024-50460

CVE, Research URL

CVE-2024-50460

Date
Oct 28, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS.This issue affects Firelight Lightbox: from n/a through 2.3.3.
Affected versions
Min -, max -.
Status
vulnerable
Jul 24, 2024

Easy FancyBox – WordPress Lightbox Plugin # PSC-2024-64504

PSC, Research URL

PSC-2024-64504

Date
-
Research Description
The “Easy FancyBox” plugin, a recipient of the Plugin Security Certification (PSC) from CleanTalk, offers a secure and feature-rich solution for implementing lightboxes on WordPress websites. With over 200,000 active installations, this plugin is renowned for its lightweight and flexible functionality, providing users with a seamless experience for viewing images and media content.
Affected versions
Min -, max -.
Status
SAFE & CERTIFIED
Jun 06, 2024

Easy FancyBox – WordPress Lightbox Plugin # CVE-2019-16524

CVE, Research URL

CVE-2019-16524

Date
Sep 26, 2019
Research Description
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
Affected versions
Min -, max -.
Status
vulnerable