Input validation vulnerability in Firelight Lightbox 2.3.15

The Firelight Lightbox tool for WordPress has a security issue where harmful code can be injected into posts. This can happen in versions 2.3.15 and below when the jQuery Metadata library is turned on. This means that someone with Contributor-level access or higher can insert their own code into a page and it will run whenever someone views that page.

Detected in:

Firelight Lightbox fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.