CVE-2026-6454: Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute
The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is string-concatenated directly into an HTML string without escaping, allowing a stored href containing entity-encoded double-quotes to break out of the data attribute and inject arbitrary event handlers into the DOM. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that execute whenever a user clicks the malicious PDF link.
Security readout for executives and security teams
Plain-English summary
A logged-in WordPress contributor can plant a malicious PDF link that runs script in another visitor’s browser when clicked. This could enable account actions or data access within the victim’s permissions. The issue affects Firelight Lightbox through version 2.3.20, according to the supplied description.
Executive priority
Prioritize affected public sites with numerous or untrusted contributors, especially where administrators may click submitted PDF links. Address promptly through a vendor-confirmed update or temporary feature isolation. Lower urgency is reasonable where contributor access is tightly controlled and no affected PDF workflow exists.
Technical view
The FancyBox V2 PDF beforeLoad callback inserts this.href into HTML without adequate escaping. Entity-encoded quotation marks can escape the intended data attribute and introduce event handlers, producing stored DOM cross-site scripting. Exploitation requires contributor-level or higher access and a victim clicking the crafted PDF link.
Likely exposure
Exposure is most likely on WordPress sites running Firelight Lightbox 2.3.20 or earlier, permitting untrusted contributor accounts, and using PDF lightbox links. Sites without the plugin, without affected versions, or without such content workflows are unlikely to be exposed.
Exploitation context
The supplied record does not report active exploitation and the CVE is not listed as KEV. An attacker needs an authenticated contributor-level account or greater, plus malicious content containing a PDF link. The description says execution occurs when a user clicks that link; this conflicts with the supplied CVSS UI:N designation.
Researcher notes
The affected-version field in the bundle contains only "0" with defaultStatus "unaffected," conflicting with the narrative limit of 2.3.20. No fixed version is explicitly identified. The linked WordPress source and changeset support code-level investigation, but the supplied material does not establish exploitation in the wild.
Mitigation direction
Check vendor guidance and upgrade to a version explicitly confirmed to address CVE-2026-6454.
Temporarily disable the plugin or affected PDF lightbox functionality where operationally acceptable.
Remove unnecessary contributor accounts and reduce untrusted users’ publishing capabilities.
Review and remove suspicious PDF links submitted by contributor-level users.
Validation and detection
Inventory Firelight Lightbox installations and record each installed version.
Identify sites running version 2.3.20 or earlier.
Review contributor-created content for unexpected or recently changed PDF links.
Confirm the vendor-designated fixed release is installed after remediation.
Verify suspicious PDF content no longer creates unintended DOM event attributes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.