CVE-2016-10865: 23systems Lightbox Plus Colorbox

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.

Affected products

  • 23systems Lightbox Plus Colorbox: up to and including 2.7.2

Published 2019-08-09. Last modified 2026-06-17.