WordPress Plugin Vulnerabilities

Colorbox Lightbox < 1.1.5 - Contributor+ Stored Cross-Site Scripting

Description

The ‘hyperlink’ field in used while linking an image from a URL was found to be vulnerable to stored XSS, as they did not sanitize user given input properly before publishing the post. It is triggered when a users loads a page where the plugin shortcode is used.

Proof of Concept

Affects Plugins

Fixed in 1.1.5

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Melbin K Mathew
Verified
Yes

Timeline

Publicly Published
2020-08-17 (about 5 years ago)
Added
2020-08-17 (about 5 years ago)
Last Updated
2022-04-09 (about 4 years ago)

Other