The Responsive Lightbox plugin for WordPress has a security issue that affects versions 2.4.5 and earlier. An attacker with author-level access or above can use the ‘name’ parameter to inject malicious web scripts into pages. When a user visits these pages, the malicious scripts will execute, putting the site and user at risk.