Dfactory develops a focused set of WordPress plugins spanning lightbox galleries, file downloads, and content engagement tools that are deployed across many websites despite the vendor's narrow product footprint. Vulnerabilities affecting these plugins skew toward serious outcomes, concentrating in web-tier weakness classes including cross-site scripting and missing authorization controls that are characteristic of plugin-layer input handling and access-management flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dfactory over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56041HIGH Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2024-43924CRITICAL Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a | Oct 23, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-31252HIGH Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2017-2243MEDIUM Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | Jul 7, 2017 | 6.1 | 22 | NO | NO |
CVE-2026-39616MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Securit | Apr 8, 2026 | 5.3 | 21 | NO | NO |
CVE-2025-3742MEDIUM The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow us | May 15, 2025 | 6.8 | 19 | NO | NO |
CVE-2023-0076MEDIUM The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is | Mar 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-49282MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox responsive-lightbox allows Stored XSS.This issue | Oct 17, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-6870MEDIUM The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient | Aug 22, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-3230MEDIUM The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1 | Jun 4, 2024 | 6.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dfactory.
Media articles that mention a CVE ID that affects a product developed by Dfactory — matched by CVE ID, not by vendor name.