The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators. | |
Title | jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-12T06:00:03.695Z
Reserved: 2025-04-15T15:37:19.392Z
Link: CVE-2025-3650

No data.

Status : Received
Published: 2025-09-12T06:15:42.587
Modified: 2025-09-12T06:15:42.587
Link: CVE-2025-3650

No data.

No data.