CVE-2016-10865

Publication date

2019-08-09 12:35:45

Family

mitre

State

PUBLISHED

Description

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.