Description
The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Published: 2025-09-12
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-29024 The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
History

Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Jquery
Jquery colorbox Plugin
Wordpress
Wordpress wordpress
Vendors & Products Jquery
Jquery colorbox Plugin
Wordpress
Wordpress wordpress

Fri, 12 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 06:15:00 +0000

Type Values Removed Values Added
Description The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Title jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS
References

Subscriptions

Jquery Colorbox Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-09-12T16:29:28.056Z

Reserved: 2025-04-15T15:37:19.392Z

Link: CVE-2025-3650

cve-icon Vulnrichment

Updated: 2025-09-12T16:28:30.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-12T06:15:42.587

Modified: 2025-09-15T15:21:42.937

Link: CVE-2025-3650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-15T10:43:59Z

Weaknesses

No weakness.