The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
Conclusion & alert: CVE-2025-3597 is rated Exploit Available (57/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.29%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-09 | 0.18% | 0.29% | +0.10% |
| 2 | 2026-03-08 | 0.05% | 0.18% | +0.13% |
| 3 | 2026-01-26 | — | 0.05% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
1.7 | 3.7 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| firelightwp | firelight_lightbox | < 2.3.15 | cpe:2.3:a:firelightwp:firelight_lightbox:*:*:*:*:*:wordpress:*:* |
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/8bf5e107-6397-4946-aaee-bf61d3e2dffd/ | Exploit Third Party Advisory |