CVE-2025-15386

Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.


We have discovered 51,214 live websites that are affected by CVE-2025-15386.

Run a Free Instant Scan




Affected Software

Product  Responsive Lightbox and Gallery
Category Wordpress Plugins
Vulnerable Domains51,214 live websites (69% of Responsive Lightbox and Gallery install base)
Vulnerable Versions
  • from 1.7 through 2.6.1
Vulnerable Versions Count35 versions ( 60% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 24, 2026
  • Updated - Feb 24, 2026

Credits

  • Matthew Rollings (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-15386
United States9,252 websites



Germany7,556 websites
Japan4,936 websites
France2,885 websites
Poland2,768 websites
Russia2,767 websites
Italy2,238 websites
GB2,010 websites
Netherlands1,932 websites
Czech Republic1,278 websites

Website Distribution by TLD

Number of websites using CVE-2025-15386
.com16,539 websites
.de5,073 websites
.ru2,227 websites
.pl2,077 websites
.org1,767 websites
.nl1,759 websites
.it1,593 websites
.co.uk1,298 websites
.net1,247 websites
.fr1,246 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-15386

Top websites that are affected by CVE-2025-15386. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******************.ro Romania**,***
***************.com Singapore**,***
************.com Israel**,***
****************.com France**,***
**********.id Indonesia**,***
*******.net United States**,***
*************.com United States**,***
***************.it Italy**,***
***********.com United States**,***
***********.com United States**,***
See full domain list

FAQ

CVE-2025-15386 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Responsive Lightbox and Gallery
A total of 51,214 websites have been identified as vulnerable to CVE-2025-15386, based on global website indexing conducted by WebTechSurvey.
The Responsive Lightbox and Gallery is affected by the CVE-2025-15386 vulnerability.
Responsive Lightbox and Gallery versions up to 2.6.1 are vulnerable to CVE-2025-15386.
CVE-2025-15386 is resolved in version 2.6.1 of Responsive Lightbox and Gallery.