The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
We have discovered 893 live websites that are affected by CVE-2026-13605.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 893 live websites (10% of Lightbox Photoswipe install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 49 versions ( 53% of all versions) |
| 75 websites | |
| 107 websites | |
| 103 websites | |
| 100 websites | |
| 97 websites | |
| 38 websites | |
| 35 websites | |
| 27 websites | |
| 20 websites | |
| 19 websites |
| .com | 245 websites |
| .pl | 85 websites |
| .ru | 71 websites |
| .de | 61 websites |
| .jp | 32 websites |
| .it | 24 websites |
| .org | 23 websites |
| .net | 22 websites |
| .cz | 22 websites |
| .co.jp | 18 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.tr | ***,*** | ||
| ****.gr | ***,*** | ||
| *****.org | ***,*** | ||
| ********.pl | ***,*** | ||
| ****.edu | ***,*** | ||
| *********.pl | ***,*** | ||
| ****.*****.com | ***,*** | ||
| *******************.de | ***,*** | ||
| ***********************.eu | ***,*** | ||
| ****************.jp | ***,*** |
FAQ