Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Responsive Lightbox — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
responsive-lightbox
- 100000+ instalaciones activas
galleriesgalleryimageimageslightbox
Estado de mantenimiento
- Última versión conocida: 2.7.8
- Requiere PHP: 7.0+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
13 CVEs conocidos registrados para Responsive Lightbox.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-56041
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.7.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 2.7.7
|
2.7.7 |
2026-06-24 |
✓ corregido en la última versión
|
|
CVE-2025-15386
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
8,8
|
< 2.6.1
|
2.6.1 |
2026-02-03 |
✓ corregido en la última versión
|
|
CVE-2025-12359
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.4 |
Falsificación de petición del lado del servidor (SSRF) |
Media
5,4
|
< 2.5.4
|
2.5.4 |
2025-11-18 |
✓ corregido en la última versión
|
|
CVE-2025-60452
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.5.3
|
2.5.3 |
2025-10-03 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2.4.9
|
2.4.9 |
2024-12-03 |
✓ corregido en la última versión
|
|
CVE-2024-49282
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,9
|
< 2.4.9
|
2.4.9 |
2024-10-15 |
✓ corregido en la última versión
|
|
CVE-2024-43924
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.8 |
Falta de control de autorización |
Crítica
9,8
|
< 2.4.8
|
2.4.8 |
2024-08-26 |
✓ corregido en la última versión
|
|
CVE-2024-6870
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.4.8
|
2.4.8 |
2024-08-21 |
✓ corregido en la última versión
|
CVE-2026-56041
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-15386
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-12359
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-60452
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.9
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-49282
The Responsive Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-43924
The Responsive Lightbox plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_builder() function in versions up to, and including, 2.4.7. This makes it possible for unauthenticated attackers to flush rules.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-6870
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 11 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-31252
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.7 |
Falta de control de autorización |
Alta
8,8
|
< 2.4.7
|
2.4.7 |
2024-04-05 |
✓ corregido en la última versión
|
|
CVE-2023-49174
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,9
|
< 2.4.6
|
2.4.6 |
2023-11-29 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.2 |
— |
Desconocido
|
< 2.4.2
|
2.4.2 |
2022-11-04 |
✓ corregido en la última versión
|
|
CVE-2017-2243
|
Responsive Lightbox & Gallery [responsive-lightbox] < 1.7.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.7.2
|
1.7.2 |
2016-12-01 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 1.4.12 |
— |
Desconocido
|
< 1.4.12
|
1.4.12 |
2015-05-14 |
✓ corregido en la última versión
|
|
CVE-2013-6837
|
Responsive Lightbox & Gallery [responsive-lightbox] < 1.4.12 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 1.4.12
|
1.4.12 |
2013-12-19 |
✓ corregido en la última versión
|
|
CVE-2024-5667
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2.4.8
|
2.4.8 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,8
|
< 2.5.1
|
2.5.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2479
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.7.2 |
— |
Desconocido
|
< 2.7.2
|
2.7.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.2 |
— |
Media
5,4
|
< 2.5.2
|
2.5.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.3 |
— |
Desconocido
|
< 2.5.3
|
2.5.3 |
0000-00-00 |
✓ corregido en la última versión
|
CVE-2024-31252
Update the WordPress Responsive Lightbox plugin to the latest available version (at least 2.4.7).
emad discovered and reported this Broken Access Control vulnerability in WordPress Responsive Lightbox Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.4.7.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-49174
Update the WordPress Responsive Lightbox plugin to the latest available version (at least 2.4.6).
emad discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Responsive Lightbox Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.4.6.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.2
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sanitize_field’ function in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping on text fields. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2017-2243
The WordPress plugin "Responsive Lightbox" provided by dFactory contains a reflected cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
Responsive Lightbox & Gallery [responsive-lightbox] < 1.4.12
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2013-6837
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5667
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.1
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2479
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.2
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SwipeBox in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.3
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Mantén Responsive Lightbox actualizado — 2.7.8 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas