PLUGIN SECURITY

Is Easy Fancybox safe?

Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.

What this plugin does

  • Slug: easy-fancybox
  • Author: Firelight
  • 200000+ active installs
  • 96/100 rating (355 reviews on wordpress.org)
  • 7853116 all-time downloads
  • On WordPress.org since 2010-08-06

galleryimagelightboxmodalphoto

Maintenance status

  • Latest known version: 2.3.22
  • Last updated: 2026-07-16 9:17pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

7 known CVEs on file for Easy Fancybox.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-52707 Firelight Lightbox [easy-fancybox] < 2.3.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.3.17 2.3.17 2025-06-19 ✓ fixed in latest
Firelight Lightbox [easy-fancybox] < 2.3.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.3.4 2.3.4 2024-12-03 ✓ fixed in latest
CVE-2024-50460 Firelight Lightbox [easy-fancybox] < 2.3.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.3.4 2.3.4 2024-10-24 ✓ fixed in latest
CVE-2019-16524 Firelight Lightbox [easy-fancybox] < 1.8.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.8.18 1.8.18 2019-09-25 ✓ fixed in latest
Firelight Lightbox [easy-fancybox] < 2.3.15 Medium 5.9 < 2.3.15 2.3.15 0000-00-00 ✓ fixed in latest
Firelight Lightbox [easy-fancybox] < 2.3.16 Medium 5.4 < 2.3.16 2.3.16 0000-00-00 ✓ fixed in latest
Firelight Lightbox [easy-fancybox] < 2.3.21 Unknown < 2.3.21 2.3.21 0000-00-00 ✓ fixed in latest
CVE-2024-5020 Multiple Plugins - Contributor+ DOM-Based Stored XSS via FancyBox JavaScript Library Unknown < 2.3.4 2.3.4 ✓ fixed in latest
+ 3 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-3597 Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS Unknown < 2.3.15 2.3.15 ✓ fixed in latest
CVE-2025-5035 Firelight Lightbox < 2.3.16 - Contributor+ Stored XSS Unknown < 2.3.16 2.3.16 ✓ fixed in latest
CVE-2026-6454 Firelight Lightbox < 2.3.21 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute Unknown < 2.3.21 2.3.21 ✓ fixed in latest

How to fix it

Keep Easy Fancybox updated — 2.3.22 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.