Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8vx-g6gq-xpj4

Опубликовано: 12 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

EPSS

Процентиль: 15%
0.00048
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
nvd
5 месяцев назад

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

EPSS

Процентиль: 15%
0.00048
Низкий

3.5 Low

CVSS3