cleantalk
Vulnerabilities and Security Researches

Responsive Lightbox & Gallery, CVE-2025-15386

CVE, Research URL

CVE-2025-15386

Published on
Feb 24, 2026
Research Description
The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.
Affected versions
max 2.6.1.
Status
vulnerable