What is CVE-2026-14833?
CVE-2026-14833 is a Stored XSS vulnerability in the 'Lightbox with PhotoSwipe' WordPress plugin before version 5.9.0. It allows users with author-level access and above to inject JavaScript via an unsanitized link data attribute, which executes in the browser when the lightbox caption is rendered. Users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-14833 'Lightbox with PhotoSwipe' WordPress plugin-inin 5.9.0-dən əvvəlki versiyalarında aşkarlanmış Stored XSS zəifliyidir. Plugin link data atributunu təmizləmədən brauzerdə göstərdiyi üçün, 'Author' və daha yuxarı səlahiyyətli istifadəçilər ('unfiltered_html' icazəsi olmadan) JavaScript kodu yerləşdirə bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: WordPress
FAQ2
How does CVE-2026-14833 affect the 'Lightbox with PhotoSwipe' plugin?
This Stored XSS vulnerability allows Author-level users and above to inject JavaScript via the link data attribute, which the plugin fails to sanitize before rendering.
What should I do to fix the CVE-2026-14833 vulnerability?
You should update the plugin to version 5.9.0 or higher immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.