ZeroHour

CVE-2025-3650

CVSS 3.1
3.5 low
EPSS
<1%p8
Published
()
Modified
Description

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.