WPIntell

Source evidence

Library with vulnerability

Responsive Lightbox & Gallery · support · 2026-01-13T20:49:00+00:00

questionsentiment
highseverity
0.82relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

9 / 37 rows with source links

24.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
digex17 resolved
The DOMPurify library version 3.1.7 has known vulnerabilities (see: https://security.snyk.io/package/npm/dompurify/3.1.7 ). A vulnerability was published on February 14, 2025, nearly a year ago, and multiple new versions have been released since then. The current recommendation is to use version 3.2.4 or higher to avoid the XSS vulnerability identified in version 3.1.7. The latest version available is 3.3.1. Is it possible to upgrade the library to mitigate the current vulnerabilities? Thank you for your feedback. The fix has already been implemented and will be included in the upcoming 2.6.1 release. What is the release date for the new version? Thank you! Changelog 2.6.1 Security: Fix potential XSS vulnerability in comment lightbox content Security: Update DOMPurify to 3.3.1 to fix known XSS vulnerability https://wordpress.org/plugins/responsive-lightbox/#developers

Comments

3 shown
weiser 2026-01-14T20:39:00+00:00

Thank you for your feedback. The fix has already been implemented and will be included in the upcoming 2.6.1 release.

digex17 2026-01-14T21:46:00+00:00

What is the release date for the new version? Thank you!

photoMaldives 2026-01-21T07:48:00+00:00

Changelog 2.6.1 Security: Fix potential XSS vulnerability in comment lightbox content Security: Update DOMPurify to 3.3.1 to fix known XSS vulnerability https://wordpress.org/plugins/responsive-lightbox/#developers