Simply Gallery Blocks with Lightbox
cpe:2.3:a:simplygallery:simply_gallery_blocks_with_lightbox:*:*:*:*:wordpress:*:*
- <= 2.2.0
A stored cross-site scripting vulnerability exists in the WordPress plugin Simply Gallery Blocks with Lightbox, in versions through 2.2.0. This vulnerability allows users with low privileges to execute arbitrary script code within the application context. The issue arises from inadequate validation of image parameters in the metadata, particularly in the Lightbox feature.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, create or edit a gallery and add media with a payload in the title field, such as a script tag including JavaScript code, such as an alert script. Once the gallery is saved, the injected script will execute when the gallery is viewed.
Users are advised to update the Simply Gallery Blocks with Lightbox plugin to version 2.2.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.