CVE-2025-15386: Unknown Responsive Lightbox & Gallery

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

Affected products

  • Unknown Responsive Lightbox & Gallery: from 1.7.0, before 2.6.1 (fixed in 2.6.1)

Published 2026-02-24. Last modified 2026-06-17.