Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Umut

#43723of 53,619
6.1Total CVSS
Vulnerabilities · 1
PT-2019-7661
6.1
2019-08-09
WordPress · Lightbox Plus Colorbox · CVE-2016-10865
**Name of the Vulnerable Software and Affected Versions** Lightbox Plus Colorbox plugin versions prior to 2.8 **Description** The issue concerns cross-site request forgery (CSRF) that can lead to resultant width XSS. This occurs via the "wp-admin/admin.php?page=lightboxplus" API endpoint. **Recommendations** For versions prior to 2.8, update to version 2.8 or later to resolve the issue.