
CVE-2026-3347 The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[message]` parameter in all versions up to, and inc… https://www.cve.org/CVERecord?id=CVE-2026-3347
Post summary
The text announces a stored XSS flaw in the Multi Functional Flexi Lightbox WordPress plugin, detailing the vulnerable parameter but providing no exploit, mitigation, or active attack information.
