CVE-2019-16524: STATUS301 Easy Fancybox

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

Affected products

  • STATUS301 Easy Fancybox: before 1.8.18 (fixed in 1.8.18)

Published 2019-09-26. Last modified 2026-06-17.