Files
CVEs-PoC/2016/CVE-2016-10865.md
2025-09-29 21:09:30 +02:00

813 B

CVE-2016-10865

Description

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.

POC

Reference

Github