Input validation vulnerability in Responsive Lightbox & Gallery 2.5.3

The Responsive Lightbox & Gallery plugin for WordPress has a security issue that allows unauthorized users to access and modify information from internal services. This vulnerability is present in all versions up to 2.5.3 and is caused by the plugin not properly checking user-supplied URLs when determining image dimensions for gallery items. This means that attackers with Author-level access or higher can send requests to any location, potentially compromising sensitive information.

Detected in:

Responsive Lightbox & Gallery fixed vulnerable versions: >= * <= 2.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.