CVE-2025-3745: Syedbalkhi Wp Lightbox 2

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

Affected products

  • Syedbalkhi Wp Lightbox 2: before 3.0.6.8 (fixed in 3.0.6.8)

Published 2025-06-30. Last modified 2026-06-17.