Browse all 3 CVE security advisories affecting firelightwp. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6454 | Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute — Firelight LightboxCWE-79 | 6.4 | Medium | 2026-07-24 |
| CVE-2026-4379 | LightPress Lightbox <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'group' Shortcode Attribute — LightPress LightboxCWE-79 | 6.4 | Medium | 2026-04-08 |
| CVE-2024-5425 | WP jQuery Lightbox <= 1.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Attribute — LightPress LightboxCWE-79 | 6.4 | Medium | 2024-06-07 |
This page lists every published CVE security advisory associated with firelightwp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.