CVE-2016-10865
09.08.2019, 13:15
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
Vendor | Product | Version |
---|---|---|
23systems | lightbox_plus_colorbox | 𝑥 ≤ 2.7.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References