CVE

CVE-2026-14833 — Lightbox with PhotoSwipe [lightbox-photoswipe] < 5.9.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14833 Lightbox with PhotoSwipe [lightbox-photoswipe] < 5.9.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.9.0 5.9.0 2026-07-13

CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin prior to version 5.9.0 fails to properly cleanse URL data attributes before displaying them within image captions, enabling authors and higher-level users without the ability to execute unfiltered HTML to insert malicious JavaScript code that executes when a visitor or administrator views the lightbox. This vulnerability allows such users to inject arbitrary script execution with minimal privileges required.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.