The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
History

Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Jquery
Jquery colorbox Plugin
Wordpress
Wordpress wordpress
Vendors & Products Jquery
Jquery colorbox Plugin
Wordpress
Wordpress wordpress

Fri, 12 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 06:15:00 +0000

Type Values Removed Values Added
Description The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Title jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-09-12T06:00:03.695Z

Updated: 2025-09-12T16:29:28.056Z

Reserved: 2025-04-15T15:37:19.392Z

Link: CVE-2025-3650

cve-icon Vulnrichment

Updated: 2025-09-12T16:28:30.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-12T06:15:42.587

Modified: 2025-09-15T15:21:42.937

Link: CVE-2025-3650

cve-icon Redhat

No data.