Security Advisory

CVE-2025-3745

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-06-30 06:00:01
Last updated 2025-06-30 18:52:02
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.