Vulnerability Description
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Firelightwp | Firelight Lightbox | < 2.3.15 |
References
- https://wpscan.com/vulnerability/8bf5e107-6397-4946-aaee-bf61d3e2dffd/ExploitThird Party Advisory
FAQ
What is CVE-2025-3597?
CVE-2025-3597 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this ...
How severe is CVE-2025-3597?
CVE-2025-3597 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3597?
Check the references section above for vendor advisories and patch information. Affected products include: Firelightwp Firelight Lightbox.