cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forauto-thickbox auto-thickbox

Direction: descending
Jul 05, 2025

Auto Thickbox # 3ec8c103834f70650b61fa3cc46bc2b4a3c7abbf

Application

Auto Thickbox

Date
-
Research Description
Auto Thickbox [auto-thickbox] <= 3.5 (unfixed) Multiple Plugins &lt;= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable