The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.
We have discovered 51,214 live websites that are affected by CVE-2025-15386.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 51,214 live websites (69% of Responsive Lightbox and Gallery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 35 versions ( 60% of all versions) |
| 9,252 websites | |
| 7,556 websites | |
| 4,936 websites | |
| 2,885 websites | |
| 2,768 websites | |
| 2,767 websites | |
| 2,238 websites | |
| 2,010 websites | |
| 1,932 websites | |
| 1,278 websites |
| .com | 16,539 websites |
| .de | 5,073 websites |
| .ru | 2,227 websites |
| .pl | 2,077 websites |
| .org | 1,767 websites |
| .nl | 1,759 websites |
| .it | 1,593 websites |
| .co.uk | 1,298 websites |
| .net | 1,247 websites |
| .fr | 1,246 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******************.ro | **,*** | ||
| ***************.com | **,*** | ||
| ************.com | **,*** | ||
| ****************.com | **,*** | ||
| **********.id | **,*** | ||
| *******.net | **,*** | ||
| *************.com | **,*** | ||
| ***************.it | **,*** | ||
| ***********.com | **,*** | ||
| ***********.com | **,*** |
FAQ