CVE-2025-3650
BaseFortify
Publication date: 2025-09-12
Last updated on: 2025-09-15
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | wordpress | * |
| jquery | colorbox | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability exists in the jQuery Colorbox WordPress plugin up to version 4.6.3, which uses the colorbox library. This library does not sanitize title attributes on links before using them, allowing users with at least the contributor role to perform cross-site scripting (XSS) attacks against administrators.
How can this vulnerability impact me? :
This vulnerability can allow users with contributor-level access to execute XSS attacks against administrators. This could lead to unauthorized actions, theft of administrator credentials, or compromise of the administrative interface.