The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jquery
Jquery colorbox Plugin Wordpress Wordpress wordpress |
|
Vendors & Products |
Jquery
Jquery colorbox Plugin Wordpress Wordpress wordpress |
Fri, 12 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators. | |
Title | jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-09-12T06:00:03.695Z
Updated: 2025-09-12T16:29:28.056Z
Reserved: 2025-04-15T15:37:19.392Z
Link: CVE-2025-3650

Updated: 2025-09-12T16:28:30.636Z

Status : Awaiting Analysis
Published: 2025-09-12T06:15:42.587
Modified: 2025-09-15T15:21:42.937
Link: CVE-2025-3650

No data.