CVE

CVE-2026-6454 — Firelight Lightbox < 2.3.21 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6454 Firelight Lightbox < 2.3.21 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute Unknown < 2.3.21 2.3.21

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.