WordPress Plugin Vulnerabilities
Colorbox Lightbox < 1.1.5 - Contributor+ Stored Cross-Site Scripting
Description
The ‘hyperlink’ field in used while linking an image from a URL was found to be vulnerable to stored XSS, as they did not sanitize user given input properly before publishing the post. It is triggered when a users loads a page where the plugin shortcode is used.
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Melbin K Mathew
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-08-17 (about 5 years ago)
Added
2020-08-17 (about 5 years ago)
Last Updated
2022-04-09 (about 4 years ago)