CVE Alert: CVE-2025-3597

Vulnerability Summary: CVE-2025-3597
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Affected Endpoints:
No affected endpoints listed.
Published Date:
5/12/2025, 6:15:39 AM
⚠️ CVSS Score:
Exploit Status:
Not ExploitedEPS Score: 0.00018 | Ranking EPS: 0.0314
References:
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.