Логотип exploitDog
bind:CVE-2025-3650
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3650

Количество 2

Количество 2

nvd логотип

CVE-2025-3650

5 месяцев назад

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-x8vx-g6gq-xpj4

5 месяцев назад

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3650

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-x8vx-g6gq-xpj4

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVSS3: 3.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу