Impact
The Colorbox Lightbox plugin for WordPress contains an improper neutralization of input flaw that enables stored cross‑site scripting. Based on the description, it is inferred that the attack vector requires an attacker to supply malicious payloads that are persisted by the plugin and then rendered in web pages. When an attacker supplies malicious payloads that are persisted by the plugin and later rendered in web pages, the payload can execute in the browsers of other users, potentially exfiltrating data, hijacking sessions, or defacing content. This weakness is classified as CWE‑79 and allows an attacker to inject and persist arbitrary JavaScript within the site’s interface.
Affected Systems
The vulnerability affects the Noor Alam Colorbox Lightbox plugin for WordPress, versions from the earliest available through 1.1.5 inclusive. Any website that has installed the plugin in these versions is impacted.
Risk and Exploitability
With a CVSS score of 6.5 the flaw presents moderate severity. The EPSS score of less than 1 % indicates a very low likelihood of active exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to inject malicious input that is stored by the plugin and then rely on site visitors to load the compromised page, a typical stored XSS attack path.
OpenCVE Enrichment
EUVD