Image and Video Lightbox, Image PopUp Security & Risk Analysis

wordpress.org/plugins/lightbox-popup

Image and Video Lightbox is an high customizable and responsive plugin for displaying images and videos in popup.

1K active installs v2.1.9 PHP + WP 3.4.0+ Updated Feb 2, 2026
image-lightboxlightboxlightbox-gallerypopup-lightboxvideo-lightbox
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 23, 2023
Safety Verdict

Is Image and Video Lightbox, Image PopUp Safe to Use in 2026?

Generally Safe

Score 100/100

Image and Video Lightbox, Image PopUp has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 23, 2023Updated 2mo ago
Risk Assessment

The "lightbox-popup" plugin v2.1.9 shows a generally good security posture, with a clean bill of health in static and taint analysis regarding critical vulnerabilities like unsanitized paths or dangerous functions. The plugin demonstrates good practices by using prepared statements for all SQL queries and performing output escaping on a high percentage of outputs. The presence of a nonce check is also a positive indicator of security awareness.

However, the vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This suggests a historical tendency towards input sanitization weaknesses. The lack of capability checks on the single AJAX handler is a potential concern, as it could allow unauthorized users to trigger its functionality if an attacker can bypass the nonce check or if the nonce check is not robust enough. The absence of REST API routes and shortcodes, while reducing the attack surface, also means fewer potential entry points are being scrutinized.

In conclusion, while the current version of "lightbox-popup" appears to have addressed past vulnerabilities and follows several secure coding practices, the lack of explicit capability checks on its sole AJAX handler presents a notable risk. The past XSS vulnerability warrants continued vigilance regarding input handling, even with the current high rate of output escaping.

Key Concerns

  • Missing capability checks on AJAX handler
  • Past medium XSS vulnerability
Vulnerabilities
1

Image and Video Lightbox, Image PopUp Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-24004medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image and Video Lightbox, Image Popup <= 2.1.5 - Authenticated (Admin+) Stored Cross-Site Scripting

Jan 23, 2023 Patched in 2.1.6 (365d)
Code Analysis
Analyzed Mar 16, 2026

Image and Video Lightbox, Image PopUp Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
137 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped150 total outputs
Attack Surface

Image and Video Lightbox, Image PopUp Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpdevart_lightbox_page_saveincludes\admin_menu.php:20
WordPress Hooks 5
actionadmin_menuincludes\admin_menu.php:17
filterthe_contentincludes\front_end.php:20
actionwp_headincludes\front_end.php:21
actionwp_headincludes\front_end.php:22
actioninitwpdevart_lightbox.php:93
Maintenance & Trust

Image and Video Lightbox, Image PopUp Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads190K

Community Trust

Rating66/100
Number of ratings12
Active installs1K
Developer Profile

Image and Video Lightbox, Image PopUp Developer Profile

wpdevart

45 plugins · 52K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
581 days
View full developer profile
Detection Fingerprints

How We Detect Image and Video Lightbox, Image PopUp

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightbox-popup/includes/javascript/wpdevart_lightbox_front.js/wp-content/plugins/lightbox-popup/includes/javascript/wpdevart_lightbox_admin_scripts.js/wp-content/plugins/lightbox-popup/includes/style/wpdevart_lightbox_front.css/wp-content/plugins/lightbox-popup/includes/style/admin_wpdevart_lightbox.css/wp-content/plugins/lightbox-popup/includes/style/effects_lightbox.css/wp-content/plugins/lightbox-popup/includes/style/jquery-ui-style.css/wp-content/plugins/lightbox-popup/images/menu_icon.png

HTML / DOM Fingerprints

CSS Classes
wpdevart_lightbox
Data Attributes
data-lightbox-settings
JS Globals
wpdevart_lightbox_obj
FAQ

Frequently Asked Questions about Image and Video Lightbox, Image PopUp