• Resolved rftbdev

    (@rftbdev)


    The iThemes Security plugin flagged the WP Colorbox plugin for a cross-site scripting issue. See report:

    title          => Colorbox Lightbox <= 1.1.2 - Authenticated Stored Cross-Site Scripting
                                fixed_in       => null
                                references     => Array
                                    0   => Array
                                        slug    => url
                                        label   => URL
                                        refs    => Array( 2 )
                                    1   => Array
                                        slug    => exploitdb
                                        label   => ExploitDB
                                        refs    => Array( 1 )
                                type           => Array
                                    label   => Cross Site Scripting
                                    slug    => xss
                                id             => wpvdb-149e5f5f-d1d8-47c6-926b-7a5fb1630b84
                                created_at     => 2020-08-17T19:39:02.000Z
                                updated_at     => 2020-12-30T06:00:45.000Z
                                published_at   => 2020-08-17T00:00:00.000Z
                                score          => 3.5
                                score_group    => low
                                score_vector   => CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
                        link       => https://itsec-site-scanner.ithemes.com/vulnerability-details/djIubG9jYWwuMDNkekRuQUJHXzlJMjJYLWMzRWdlQU1lV1Z5eVRxUnFwR0pvc1pHU3NnTWx5Y2RLcWFTMk1rTUZGYUxkanpJUkFQVXhkdTdOUU9TSlZJWlVaa1NzNEl5dmhJZHduai1VUjRuTnNEcjUyODJhTzFZUjhDOWxKT2dPRU9XMGV5QWcxcWZVNldsSm5BazdIWjc2SFVyTkI3YUg2YW43X1FoclA3V3BrTFdwVm5BZmZoRFAyNzN2YTBONm5nUW9FQUYxVnJOdnNpb3F6X2NUVGlIUUlvSDBlTm9KX1dkUUN6NWN2MEx6a3dvR3hNc3hKRjAxVFFvdlNZXzZiWm1wTDZ2UjVHb0RuYmtzdDFycmU5RHpMcEVuaXMwWk9EZ3ZNWng3eVhXWGplX29nVFFyRmJKbGZoTHQ5QlBMMFhrbnNWM1psNE81MGQ1SVkzLThQb0xTM3RUMGRrWkdXRDMxTmRCOS1FdGxpOV9pNjhLTUJWMFVzOG5MdzUwY2o1TFNSVkRJelBveVRDcDNDS3NVRHc%253D

    I just want to make sure you’re aware of the risk, and to see if you will have an update soon?

    Thank you.

  • The topic ‘Cross-Site Scripting Issue’ is closed to new replies.