← WordPress Vulnerabilities
WordPress security by component

Responsive Lightbox

Responsive Lightbox is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: responsive-lightbox

CVE-2026-56041: Responsive Lightbox: Cross-site scripting

Responsive Lightbox is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.6.

PublishedJun 26, 2026
Known safe version2.7.7
Safe version
Jun 26, 2026 CVE-2026-56041
Responsive Lightbox: Cross-site scripting
Responsive Lightbox is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.6.
2.7.7
CVE7.1
NVDPending
Feb 25, 2026 CVE-2026-2479
Responsive Lightbox & Gallery: Server-side request forgery
Responsive Lightbox & Gallery is affected by server-side request forgery. Exploitation requires at least author-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.0
NVDPending
Nov 19, 2025 CVE-2025-12359
Responsive Lightbox & Gallery: Server-side request forgery
Responsive Lightbox & Gallery is affected by server-side request forgery. Exploitation requires at least author-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.4
NVDPending
Jun 27, 2025 CVE-2025-5093
Responsive Lightbox & Gallery: Cross-site scripting
Responsive Lightbox & Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2025-3742
Responsive Lightbox & Gallery: Cross-site scripting
Responsive Lightbox & Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVDPending
Oct 23, 2024 CVE-2024-43924
Responsive Lightbox: A security weakness
Responsive Lightbox is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Oct 17, 2024 CVE-2024-49282
Responsive Lightbox: Cross-site scripting
Responsive Lightbox is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Aug 22, 2024 CVE-2024-6870
Responsive Lightbox & Gallery: Cross-site scripting
Responsive Lightbox & Gallery is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 09, 2024 CVE-2024-31252
Responsive Lightbox: A security weakness
Responsive Lightbox is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Dec 15, 2023 CVE-2023-49174
Responsive Lightbox & Gallery: Cross-site scripting
Responsive Lightbox & Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD5.4
Jul 07, 2017 CVE-2017-2243
Responsive Lightbox: Cross-site scripting
Responsive Lightbox is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1