CVE-2026-6454 | firelightwp Firelight Lightbox Plugin up to 2.3.20 on WordPress JavaScript Callback inc/fancybox-2.php beforeLoad href cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in firelightwp Firelight Lightbox Plugin up to 2.3.20 on WordPress. This affects the function beforeLoad of the file inc/fancybox-2.php of the component JavaScript Callback Handler. Executing a manipulation of the argument href can lead to cross site scripting.

This vulnerability is handled as CVE-2026-6454. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More