Impact
The Simple Colorbox plugin contains a stored XSS vulnerability caused by improper neutralization of user input. This weakness allows malicious JavaScript to be embedded into content that is subsequently rendered on pages for all visitors. The resulting impact is unintended script execution in the context of the site, which could lead to cookie theft, defacement, or other malicious actions against legitimate users.
Affected Systems
WordPress sites installing the Simple Colorbox plugin version 1.6.1 or earlier. The plugin, developed by Ryan Hellyer, is distributed under the Simple Colorbox name and is integrated into WordPress sites via its plugin mechanism.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is through the plugin’s input forms where an attacker can submit malicious content that is stored. The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to submit malicious content through the plugin’s input mechanisms, which can then be stored and displayed to all site visitors.
OpenCVE Enrichment
EUVD