CVE-2025-3597
MEDIUMDescription
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Is your site exposed to CVE-2025-3597?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| firelightwp | firelight_lightbox |
References
Frequently Asked Questions
What is CVE-2025-3597? +
How severe is CVE-2025-3597? +
What products are affected by CVE-2025-3597? +
How do I check if I'm vulnerable to CVE-2025-3597? +
Related Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firelight Firelight Lightbox easy-fancybox allows Stored XSS.This issue …
The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, …