Security Advisory

CVE-2016-10865

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-08-09 12:35:45
Last updated 2024-08-06 03:38:56
Assigner mitre
State PUBLISHED

Description

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.