WordPress Plugin Vulnerabilities

jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS

Description

The plugin uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes

Timeline

Publicly Published
2025-08-22 (about 4 months ago)
Added
2025-08-22 (about 4 months ago)
Last Updated
2025-08-22 (about 4 months ago)

Other