CVE-2025-3650

low

Description

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

References

https://wpscan.com/vulnerability/5afdd448-0f7e-409e-a47b-8e5c5b707639/

Details

Source: Mitre, NVD

Published: 2025-09-12

Updated: 2025-09-12

Risk Information

CVSS v2

Base Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 3.5

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00018