CVE Alert: CVE-2025-3597

image 1

Vulnerability Summary: CVE-2025-3597

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.

Affected Endpoints:

No affected endpoints listed.

Published Date:

5/12/2025, 6:15:39 AM

⚠️ CVSS Score:

CVSS v3 Score: 5.9 (Medium)

Exploit Status:

Not Exploited

EPS Score: 0.00018 | Ranking EPS: 0.0314

References:

Recommended Action:

No proposed action available. Please refer to vendor documentation for updates.


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.