LiveActive security incident?Get immediate response
CVE Record

CVE-2026-6454: Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-concatenated directly into an HTML string without escaping, allowing a stored href containing entity-encoded double-quotes to break out of the data attribute and inject arbitrary event handlers into the DOM. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that execute whenever a user clicks the malicious PDF link.

MediumCVSS 6.4Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A logged-in WordPress contributor can plant a malicious PDF link that runs script in another visitor’s browser when clicked. This could enable account actions or data access within the victim’s permissions. The issue affects Firelight Lightbox through version 2.3.20, according to the supplied description.

Executive priority

Prioritize affected public sites with numerous or untrusted contributors, especially where administrators may click submitted PDF links. Address promptly through a vendor-confirmed update or temporary feature isolation. Lower urgency is reasonable where contributor access is tightly controlled and no affected PDF workflow exists.

Technical view

The FancyBox V2 PDF beforeLoad callback inserts this.href into HTML without adequate escaping. Entity-encoded quotation marks can escape the intended data attribute and introduce event handlers, producing stored DOM cross-site scripting. Exploitation requires contributor-level or higher access and a victim clicking the crafted PDF link.

Likely exposure

Exposure is most likely on WordPress sites running Firelight Lightbox 2.3.20 or earlier, permitting untrusted contributor accounts, and using PDF lightbox links. Sites without the plugin, without affected versions, or without such content workflows are unlikely to be exposed.

Exploitation context

The supplied record does not report active exploitation and the CVE is not listed as KEV. An attacker needs an authenticated contributor-level account or greater, plus malicious content containing a PDF link. The description says execution occurs when a user clicks that link; this conflicts with the supplied CVSS UI:N designation.

Researcher notes

The affected-version field in the bundle contains only "0" with defaultStatus "unaffected," conflicting with the narrative limit of 2.3.20. No fixed version is explicitly identified. The linked WordPress source and changeset support code-level investigation, but the supplied material does not establish exploitation in the wild.

Mitigation direction

  • Check vendor guidance and upgrade to a version explicitly confirmed to address CVE-2026-6454.
  • Temporarily disable the plugin or affected PDF lightbox functionality where operationally acceptable.
  • Remove unnecessary contributor accounts and reduce untrusted users’ publishing capabilities.
  • Review and remove suspicious PDF links submitted by contributor-level users.

Validation and detection

  • Inventory Firelight Lightbox installations and record each installed version.
  • Identify sites running version 2.3.20 or earlier.
  • Review contributor-created content for unexpected or recently changed PDF links.
  • Confirm the vendor-designated fixed release is installed after remediation.
  • Verify suspicious PDF content no longer creates unintended DOM event attributes.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-6454 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
1ADP providers
7Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.4CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N3.12.7Wordfence

Vulnerability scoring details

Base CVSS 3.1 score

6.4Medium
CVSS 3.1 vector shape for CVE-2026-6454Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. Source timelineWordfence

    Vendor Notified

  3. Source timelineWordfence

    Disclosed

  4. CVE publishedCVE Program

    The CVE record was published.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
firelightwpFirelight Lightbox0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.