CVE-2026-6454

Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-concatenated directly into an HTML string without escaping, allowing a stored href containing entity-encoded double-quotes to break out of the data attribute and inject arbitrary event handlers into the DOM. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that execute whenever a user clicks the malicious PDF link.


We have discovered 25,252 live websites that are affected by CVE-2026-6454.

Run a Free Instant Scan




Affected Software

Product  Easy Fancybox
Category Wordpress Plugins
Vulnerable Domains25,252 live websites (100% of Easy Fancybox install base)
Vulnerable Versions
  • from 0 through 2.3.20
Vulnerable Versions Count38 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 24, 2026
  • Updated - Jul 24, 2026

Credits

  • Quốc Huy (jtwings) (finder)

Website Distribution by Country

Number of websites using CVE-2026-6454
United States2,673 websites



Japan7,400 websites
Russia4,907 websites
Germany1,401 websites
France1,000 websites
Poland817 websites
Italy777 websites
Ukraine475 websites
GB470 websites
Czech Republic419 websites

Website Distribution by TLD

Number of websites using CVE-2026-6454
.com8,355 websites
.ru4,041 websites
.jp1,774 websites
.co.jp1,133 websites
.net871 websites
.de829 websites
.pl639 websites
.org559 websites
.it519 websites
.fr444 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-6454

Top websites that are affected by CVE-2026-6454. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.*******.org United States**,***
*******.com United States**,***
********.com United States**,***
******.ru Russia**,***
***********.com United States***,***
****************.com United States***,***
****************.ro Romania***,***
******.tj Russia***,***
**********.org United States***,***
*********.com United States***,***
See full domain list

FAQ

CVE-2026-6454 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Easy Fancybox
A total of 25,252 websites have been identified as vulnerable to CVE-2026-6454, based on global website indexing conducted by WebTechSurvey.
The Easy Fancybox is affected by the CVE-2026-6454 vulnerability.
Easy Fancybox versions up to and including 2.3.20 are vulnerable to CVE-2026-6454.

References