CVE-2025-9710

Publication date

2025-10-06 06:00:06

Family

WPScan

State

PUBLISHED

Description

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.