vendor:
Colorbox Lightbox
by:
n1x_ [MS-WEB]
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Colorbox Lightbox
Affected Version From: 1.1.2001
Affected Version To: 1.1.2001
Patch Exists: NO
Related CWE:
CPE: a:wordpress:wp-colorbox:1.1.1
Platforms Tested: WordPress
2020
WordPress Plugin Colorbox Lightbox v1.1.1 – Persistent Cross-Site Scripting Vulnerability (Authenticated)
WordPress Colorbox plugin version v1.1.1 (and possibly previous versions) is affected by a stored XSS vulnerability due to improper input sanitization of the "hyperlink" field in the plugin shortcode.
Mitigation:
Update to the latest version of the plugin or apply a patch provided by the vendor. Avoid using untrusted input in the "hyperlink" field.