CVE-2016-10865: 23systems Lightbox Plus Colorbox
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
Affected products
- 23systems Lightbox Plus Colorbox: up to and including 2.7.2
Published 2019-08-09. Last modified 2026-06-17.