CVE-2025-5092: DOM-Based Stored XSS in Multiple WordPress Plugins via lightGallery
Security AdvisoryCVE-2025-5092MediumWordPress
Affected:
- Gallery with thumbnail slider <= 7.8
- Ibtana – WordPress Website Builder <= 1.2.5.1
- Image Hover Effects Ultimate <= 9.10.5
- LightGallery WP <= 1.0.5
- OnePress <= 2.3.15
Fixed in:
- Ibtana – WordPress Website Builder 1.2.5.2
- Portfolio, Gallery, Product Catalog – Grid KIT 2.2.2
- Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1032
- TP WooCommerce Product Gallery 2.0.0
参照 CVE: CVE-2025-5092 · 6.4
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 www.wordfence.com 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。