Vulnerability CVE-2022-0161


Published: 2022-03-14

Description:
The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/6b37fa17-0dcb-47a7-b1eb-f9f6abb458c0
https://plugins.trac.wordpress.org/changeset/2680993

Copyright 2026, cxsecurity.com

 

Back to Top