The FancyBox for WordPress plugin before version 3.0.3 had a security vulnerability which allowed remote attackers to do something called cross-site scripting (XSS). This meant that attackers could use a certain parameter in an update action. This vulnerability was exploited in the wild in February 2015.