The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.
https://wpscan.com/vulnerability/fa3a84b6-6d5d-4e10-8587-ae49c127483b/