Input validation vulnerability in Responsive Lightbox & Gallery 2.4.8

Several plugins used on WordPress websites are at risk of a type of hacking called Stored Cross-Site Scripting. This happens because the plugins use a JavaScript library called FancyBox that is not properly protected against malicious code. As a result, attackers who have contributor-level access or higher can add their own harmful code to a webpage and trick users into running it when they visit that page.

Detected in:

Accordion Slider fixed vulnerable versions: >= * <= 1.9.12
Colibri Page Builder fixed vulnerable versions: >= * <= 1.0.286
Easy Social Feed Premium fixed vulnerable versions:
Easy Social Feed Pro fixed vulnerable versions:
FancyBox for WordPress fixed vulnerable versions: >= * <= 3.3.4
Firelight Lightbox fixed vulnerable versions:
FV Flowplayer Video Player fixed vulnerable versions: >= * <= 7.5.47.7212
Gallery Plugin for WordPress – Envira Photo Gallery fixed vulnerable versions: >= * <= 1.8.15
Getwid – Gutenberg Blocks fixed vulnerable versions: >= * <= 2.0.11
Responsive Lightbox & Gallery fixed vulnerable versions: >= * <= 2.4.8
Visual Portfolio, Photo Gallery & Post Grid fixed vulnerable versions: >= * <= 3.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.