CVE-2025-5092: Famethemes Onepress

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected products

  • Famethemes Onepress: up to and including 2.3.16
  • Galaxyweblinks Gallery With Thumbnail Slider: up to and including 7.8
  • Lightgalleryteam Lightgallery Wp: up to and including 1.0.5
  • Oxilab Image Hover Effects Ultimate Image Gallery, Effects, Lightbox, Comparison & Magnifier: up to and including 9.10.5
  • Tplugins TP Woocommerce Product Gallery: up to and including 1.1.9
  • Vowelweb Ibtana – WordPress Website Builder: up to and including 1.2.5.1
  • Wproyal Royal Addons For Elementor – Addons And Templates Kit For Elementor: up to and including 1.7.1031
  • Wpsofts Portfolio, Gallery, Product Catalog – Grid Kit Portfolio: up to and including 2.2.1

Published 2025-11-20. Last modified 2026-06-17.