Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-3662

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.0%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-3662


Contact Us

Shodan ® - All rights reserved