PatchSiren cyber security CVE debrief
CVE-2026-14833 Lightbox with PhotoSwipe CVE debrief
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox.
- Vendor
- Lightbox with PhotoSwipe
- Product
- Lightbox with PhotoSwipe WordPress plugin
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators and users of the Lightbox with PhotoSwipe WordPress plugin, especially those with author-level access or above, should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes updating the plugin to version 5.9.0 or later and restricting user access to the plugin's settings and content. Additionally, monitoring plugin usage and user activity for suspicious behavior is recommended to identify potential exploitation attempts.
Technical summary
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not properly sanitise or escape a link data attribute, allowing users with author-level access to store JavaScript that runs when a visitor or administrator opens the lightbox. This vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. The plugin's failure to sanitize user input enables the injection of malicious JavaScript, potentially leading to unauthorized actions or data exposure.
Defensive priority
Medium-priority defensive actions are recommended due to the medium CVSS score of 6.8.
Recommended defensive actions
- Apply the vendor patch to update the Lightbox with PhotoSwipe WordPress plugin to version 5.9.0 or later.
- Restrict user access to the plugin's settings and content to prevent author-level users from injecting malicious JavaScript.
- Monitor plugin usage and user activity for suspicious behavior.
- Consider implementing additional security controls, such as Content Security Policy (CSP) headers.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from the NVD and WPScan indicates that the Lightbox with PhotoSwipe WordPress plugin is vulnerable to stored JavaScript injection via a link data attribute. Further verification is needed to determine the full scope of affected versions and configurations. The vulnerability allows users with author-level access and above to store JavaScript that runs when a visitor or administrator opens the lightbox. Additional review of plugin usage and user activity is recommended to identify potential exploitation.
Official resources
-
CVE-2026-14833 CVE record
CVE.org
-
CVE-2026-14833 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:25.207Z and has not been modified since then.