CVE-2025-5092: Famethemes Onepress
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected products
- Famethemes Onepress: up to and including 2.3.16
- Galaxyweblinks Gallery With Thumbnail Slider: up to and including 7.8
- Lightgalleryteam Lightgallery Wp: up to and including 1.0.5
- Oxilab Image Hover Effects Ultimate Image Gallery, Effects, Lightbox, Comparison & Magnifier: up to and including 9.10.5
- Tplugins TP Woocommerce Product Gallery: up to and including 1.1.9
- Vowelweb Ibtana – WordPress Website Builder: up to and including 1.2.5.1
- Wproyal Royal Addons For Elementor – Addons And Templates Kit For Elementor: up to and including 1.7.1031
- Wpsofts Portfolio, Gallery, Product Catalog – Grid Kit Portfolio: up to and including 2.2.1
Published 2025-11-20. Last modified 2026-06-17.