# Meow Lightbox <= 5.6.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content

- **ID:** WPSEC-2026-0757
- **Plugin:** Meow Lightbox (`meow-lightbox`), https://wordpress.org/plugins/meow-lightbox/
- **Affected versions:** all versions before 5.6.3
- **Fixed in:** 5.6.3 (Update to 5.6.3 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/meow-lightbox
- **Fix released:** 2026-10-10
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0757/

## Description

The Meow Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comment content and other page text processed by its HTML parser in all versions up to, and including, 5.6.2. This is due to the bundled HTML parser using predictable placeholders ("___noise___ 1000") for the script, style, code and comment blocks it sets aside, and restoring any matching placeholder it finds in page text or attribute values. Unescaped content from another block is then written back in place of the placeholder when the page is re-rendered. This makes it possible for unauthenticated attackers to inject arbitrary web scripts through comments when the plugin's Output Buffering option is enabled, and for authenticated attackers with Contributor-level access and above to do so through post content in the default mode. The scripts execute whenever a user accesses an injected page.

## References

- https://wpsec.com/vuln/WPSEC-2026-0757/
- https://plugins.svn.wordpress.org/meow-lightbox/tags/5.6.3/
- https://wordpress.org/plugins/meow-lightbox/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0757/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
