Stored Cross-Site Scripting Vulnerability in Colibri Page Builder for WordPress
CVE-2023-6988
What is CVE-2023-6988?
The Colibri Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw that arises from inadequate input sanitization and output escaping of user-supplied attributes within the plugin's extend_builder_render_js shortcode. As a result, authenticated attackers who possess contributor-level permissions or higher can exploit this vulnerability to inject arbitrary web scripts into web pages. These scripts will execute whenever users access the affected pages, posing significant security risks for any site utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Colibri Page Builder * <= 1.0.239
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved