
Image and Video Lightbox, Image PopUp Security & Risk Analysis
wordpress.org/plugins/lightbox-popupImage and Video Lightbox is an high customizable and responsive plugin for displaying images and videos in popup.
Is Image and Video Lightbox, Image PopUp Safe to Use in 2026?
Generally Safe
Score 100/100Image and Video Lightbox, Image PopUp has a strong security track record. Known vulnerabilities have been patched promptly.
The "lightbox-popup" plugin v2.1.9 shows a generally good security posture, with a clean bill of health in static and taint analysis regarding critical vulnerabilities like unsanitized paths or dangerous functions. The plugin demonstrates good practices by using prepared statements for all SQL queries and performing output escaping on a high percentage of outputs. The presence of a nonce check is also a positive indicator of security awareness.
However, the vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This suggests a historical tendency towards input sanitization weaknesses. The lack of capability checks on the single AJAX handler is a potential concern, as it could allow unauthorized users to trigger its functionality if an attacker can bypass the nonce check or if the nonce check is not robust enough. The absence of REST API routes and shortcodes, while reducing the attack surface, also means fewer potential entry points are being scrutinized.
In conclusion, while the current version of "lightbox-popup" appears to have addressed past vulnerabilities and follows several secure coding practices, the lack of explicit capability checks on its sole AJAX handler presents a notable risk. The past XSS vulnerability warrants continued vigilance regarding input handling, even with the current high rate of output escaping.
Key Concerns
- Missing capability checks on AJAX handler
- Past medium XSS vulnerability
Image and Video Lightbox, Image PopUp Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Image and Video Lightbox, Image Popup <= 2.1.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Image and Video Lightbox, Image PopUp Code Analysis
Output Escaping
Image and Video Lightbox, Image PopUp Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Image and Video Lightbox, Image PopUp Maintenance & Trust
Maintenance Signals
Community Trust
Image and Video Lightbox, Image PopUp Alternatives
MetaSlider Lightbox – Modals & Lightboxes – Image, Gallery, Video, Slideshow Lightbox
ml-slider-lightbox
MetaSlider Lightbox is the lightbox and modal plugin for WordPress. Build a lightbox for images, galleries, video, slideshows and more.
Thumbnail Slider With Lightbox
wp-responsive-slider-with-lightbox
This is a beautiful responsive thumbnail slider for WordPress blogs and sites with responsive lightbox. Admin can manage any number of images into the …
Awesome Lightbox
awesome-lightbox
Awesome video lightbox plugin.
WP Video Lightbox
wp-video-lightbox
Very easy to use WordPress lightbox plugin to display YouTube and Vimeo videos in an elegant lightbox overlay.
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
Image and Video Lightbox, Image PopUp Developer Profile
45 plugins · 52K total installs
How We Detect Image and Video Lightbox, Image PopUp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lightbox-popup/includes/javascript/wpdevart_lightbox_front.js/wp-content/plugins/lightbox-popup/includes/javascript/wpdevart_lightbox_admin_scripts.js/wp-content/plugins/lightbox-popup/includes/style/wpdevart_lightbox_front.css/wp-content/plugins/lightbox-popup/includes/style/admin_wpdevart_lightbox.css/wp-content/plugins/lightbox-popup/includes/style/effects_lightbox.css/wp-content/plugins/lightbox-popup/includes/style/jquery-ui-style.css/wp-content/plugins/lightbox-popup/images/menu_icon.pngHTML / DOM Fingerprints
wpdevart_lightboxdata-lightbox-settingswpdevart_lightbox_obj