cleantalk
Vulnerabilities and Security Researches

Responsive Lightbox & Gallery, CVE-2025-12359

CVE, Research URL

CVE-2025-12359

Published on
Nov 19, 2025
Research Description
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Affected versions
max 2.5.4.
Status
vulnerable