
WP fancybox Security & Risk Analysis
wordpress.org/plugins/wp-fancyboxView image, YouTube video, Vimeo video, inline HTML in lightbox. Add fancybox lightbox effect to your WordPress site.
Is WP fancybox Safe to Use in 2026?
Mostly Safe
Score 74/100WP fancybox is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The wp-fancybox plugin version 1.0.4 exhibits a mixed security posture. On the positive side, the static analysis indicates no immediately obvious critical vulnerabilities within the code itself. There are no dangerous functions, SQL queries are all prepared, and file operations and external HTTP requests are absent. However, the analysis does highlight a concerning lack of security best practices. Specifically, there are no nonce checks or capability checks implemented, which could leave the plugin exposed if entry points were discovered or created. Additionally, a significant portion of output (30%) is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is incorporated into these outputs.
The plugin's vulnerability history is a major red flag, with two known CVEs, one of which remains unpatched. The common vulnerability type being Cross-Site Scripting, combined with the unescaped output noted in the static analysis, strongly suggests that unpatched XSS vulnerabilities are a persistent issue. The fact that the last vulnerability was dated in the near future (2025-07-04) is also peculiar and could indicate a reporting anomaly or a future known issue.
In conclusion, while the static analysis doesn't reveal immediate code execution or SQL injection flaws, the absence of critical security checks like nonces and capability checks, coupled with the history of unpatched XSS vulnerabilities and partially unescaped output, makes this plugin a significant security risk. The unpatched high-severity vulnerability is the most critical concern and should be addressed immediately.
Key Concerns
- Unpatched high severity CVE (XSS)
- Medium severity CVE (unpatched)
- Missing nonce checks
- Missing capability checks
- 30% of output not properly escaped
WP fancybox Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP fancybox <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress fancybox <= 1.0.2 - Stored Cross-Site Scripting
WP fancybox Code Analysis
Output Escaping
WP fancybox Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
WP fancybox Maintenance & Trust
Maintenance Signals
Community Trust
WP fancybox Alternatives
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Simple Lightbox
simple-lightbox
The highly customizable lightbox for WordPress
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
LightPress Lightbox
wp-jquery-lightbox
Simple, lightweight lightbox plugin for WordPress. Formerly the WP JQuery Lightbox.
WP fancybox Developer Profile
25 plugins · 157K total installs
How We Detect WP fancybox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fancybox/dist/fancybox/fancybox.css/wp-content/plugins/wp-fancybox/dist/fancybox/fancybox.js/wp-content/plugins/wp-fancybox/dist/fancybox/fancybox.jswp-fancybox/dist/fancybox/fancybox.js?ver=wp-fancybox/dist/fancybox/fancybox.css?ver=HTML / DOM Fingerprints
data-fancyboxFancybox<a href="