CVE-2025-3650

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.
Configurations

No configuration.

History

No history.

Information

Published : 2025-09-12 06:15

Updated : 2026-06-17 09:20


NVD link : CVE-2025-3650

Mitre link : CVE-2025-3650

CVE.ORG link : CVE-2025-3650


JSON object : View

Products Affected

No product.

CWE

No CWE.