Conversation
supportThe DOMPurify library version 3.1.7 has known vulnerabilities (see: https://security.snyk.io/package/npm/dompurify/3.1.7 ). A vulnerability was published on February 14, 2025, nearly a year ago, and multiple new versions have been released since then. The current recommendation is to use version 3.2.4 or higher to avoid the XSS vulnerability identified in version 3.1.7. The latest version available is 3.3.1. Is it possible to upgrade the library to mitigate the current vulnerabilities?
Thank you for your feedback. The fix has already been implemented and will be included in the upcoming 2.6.1 release.
What is the release date for the new version? Thank you!
Changelog 2.6.1 Security: Fix potential XSS vulnerability in comment lightbox content Security: Update DOMPurify to 3.3.1 to fix known XSS vulnerability https://wordpress.org/plugins/responsive-lightbox/#developers
Thank you for your feedback. The fix has already been implemented and will be included in the upcoming 2.6.1 release.
What is the release date for the new version? Thank you!
Changelog 2.6.1 Security: Fix potential XSS vulnerability in comment lightbox content Security: Update DOMPurify to 3.3.1 to fix known XSS vulnerability https://wordpress.org/plugins/responsive-lightbox/#developers