The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jquery
Jquery colorbox Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Jquery
Jquery colorbox Plugin Wordpress Wordpress wordpress |
Fri, 12 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators. | |
| Title | jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-09-12T06:00:03.695Z
Updated: 2025-09-12T16:29:28.056Z
Reserved: 2025-04-15T15:37:19.392Z
Link: CVE-2025-3650
Updated: 2025-09-12T16:28:30.636Z
Status : Awaiting Analysis
Published: 2025-09-12T06:15:42.587
Modified: 2025-09-15T15:21:42.937
Link: CVE-2025-3650
No data.