The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox. | |
| Title | Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-31T06:00:06.879Z
Reserved: 2026-07-06T09:51:49.570Z
Link: CVE-2026-14833
No data.
No data.
No data.
OpenCVE Enrichment
No data.