Security Advisory

CVE-2025-3649

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-12 06:00:03
Last updated 2025-05-12 17:03:04
Assigner WPScan
State PUBLISHED

Description

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.