Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter


Security Advisory: Easy FancyBox WordPress Plugin Stored Cross-site Scripting (CVE-2019-16524)

The Easy FancyBox WordPress Plugin Version 1.8.17 is susceptible to Stored cross-site Scripting in the Settings > Media admin page due to improper encoding of arbitrarily submitted setting parameters. The vulnerability affects every publicly accessible page of the WordPress site.

Full security advisory: https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20190911-01_Easy_FancyBox_WP_Plugin_Stored_XSS