๐Ÿ” CVE Alert

CVE-2026-14833

UNKNOWN 0.0

Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox.

Vendor unknown
Product lightbox with photoswipe
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for unknown lightbox with photoswipe

Be the first to know when new unknown vulnerabilities affecting unknown lightbox with photoswipe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Lightbox with PhotoSwipe
0 < 5.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/aae59cb8-b259-464e-a86b-164d89f61342/

Credits

Pierre Rudloff WPScan