PLUGIN SECURITY
Is Easy Fancybox safe?
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
What this plugin does
- Slug:
easy-fancybox - Author: Firelight
- 200000+ active installs
- 96/100 rating (355 reviews on wordpress.org)
- 7853116 all-time downloads
- On WordPress.org since 2010-08-06
galleryimagelightboxmodalphoto
Maintenance status
- Latest known version: 2.3.22
- Last updated: 2026-07-16 9:17pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for Easy Fancybox.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-52707 | Firelight Lightbox [easy-fancybox] < 2.3.17 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.3.17 | 2.3.17 | 2025-06-19 | ✓ fixed in latest |
| — | Firelight Lightbox [easy-fancybox] < 2.3.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.3.4 | 2.3.4 | 2024-12-03 | ✓ fixed in latest |
| CVE-2024-50460 | Firelight Lightbox [easy-fancybox] < 2.3.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.3.4 | 2.3.4 | 2024-10-24 | ✓ fixed in latest |
| CVE-2019-16524 | Firelight Lightbox [easy-fancybox] < 1.8.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.8.18 | 1.8.18 | 2019-09-25 | ✓ fixed in latest |
| — | Firelight Lightbox [easy-fancybox] < 2.3.15 | — | Medium 5.9 | < 2.3.15 | 2.3.15 | 0000-00-00 | ✓ fixed in latest |
| — | Firelight Lightbox [easy-fancybox] < 2.3.16 | — | Medium 5.4 | < 2.3.16 | 2.3.16 | 0000-00-00 | ✓ fixed in latest |
| — | Firelight Lightbox [easy-fancybox] < 2.3.21 | — | Unknown | < 2.3.21 | 2.3.21 | 0000-00-00 | ✓ fixed in latest |
| CVE-2024-5020 | Multiple Plugins - Contributor+ DOM-Based Stored XSS via FancyBox JavaScript Library | — | Unknown | < 2.3.4 | 2.3.4 | — | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-3597 | Firelight Lightbox < 2.3.15 - Contributor+ Stored XSS | — | Unknown | < 2.3.15 | 2.3.15 | — | ✓ fixed in latest |
| CVE-2025-5035 | Firelight Lightbox < 2.3.16 - Contributor+ Stored XSS | — | Unknown | < 2.3.16 | 2.3.16 | — | ✓ fixed in latest |
| CVE-2026-6454 | Firelight Lightbox < 2.3.21 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute | — | Unknown | < 2.3.21 | 2.3.21 | — | ✓ fixed in latest |
How to fix it
Keep Easy Fancybox updated — 2.3.22 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Smart Slider 3 — 800000+ active installs — 98/100 (1123) — max PHP <8.0
- Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider — 500000+ active installs — 92/100 (738) — max PHP 8.4
- Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery — 300000+ active installs — 86/100 (4339) — max PHP 8.4
- Imsanity — 200000+ active installs — 98/100 (292) — max PHP 8.4
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery — 100000+ active installs — 90/100 (1581)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.