CVE-2025-23704
Published: 26 March 2025
Description
Adversaries may abuse various implementations of JavaScript for execution.
Security Summary
CVE-2025-23704 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the Your Lightbox WordPress plugin by Reuven Karasik. The issue affects all versions of the plugin from n/a through 1.0 inclusive. Published on 2025-03-26, it carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating high severity due to its network accessibility and scope change.
Attackers can exploit this vulnerability remotely over the network with low attack complexity and no required privileges, though it demands user interaction, such as visiting a maliciously crafted URL. Upon successful exploitation, adversaries can inject and execute arbitrary scripts in the victim's browser context, achieving low impacts on confidentiality, integrity, and availability within a changed security scope, potentially enabling session hijacking, data theft, or further phishing.
The Patchstack advisory provides details on this WordPress plugin vulnerability, accessible at https://patchstack.com/database/Wordpress/Plugin/your-lightbox/vulnerability/wordpress-your-lightbox-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve. Security practitioners should consult it for recommended mitigations, such as updating the plugin or applying available patches if released.
Details
- CWE(s)
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Reflected XSS in public-facing WordPress plugin directly enables exploitation of the web application (T1190) via crafted URLs and execution of arbitrary JavaScript in the victim's browser (T1059.007).