Description

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

INFO

Published Date :

2025-11-20T06:38:41.693Z

Last Modified :

2025-11-24T19:45:25.705Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-5092 vulnerability.

Vendors Products
Famatehemes
  • Onepress
Galaxyweblinks
  • Gallery With Thumbnail Slider
Lightgalleryteam
  • Lightgallery Wp
Tplugins
  • Tp Woocommerce Product Gallery
Vowelweb
  • Ibtana
Wordpress
  • Wordpress
Wpkin
  • Image Hover Effects Ultimate
Wproyal
  • Royal Elementor Addons And Templates
Wpsofts
  • Portfolio Gallery, Product Catalog - Grid Kit Portfolio

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact