Stored Cross-Site Scripting Vulnerability in Colibri Page Builder Plugin for WordPress
CVE-2024-3338
5.4MEDIUM
What is CVE-2024-3338?
The Colibri Page Builder plugin for WordPress has a vulnerability that allows authenticated attackers with author-level access or higher to execute arbitrary web scripts. This is due to inadequate sanitization of the image alt data parameter, which can lead to Stored Cross-Site Scripting attacks. When a user visits an infected page, the injected scripts can execute, potentially compromising user data and website integrity. Immediate remediation and updating are essential to safeguard against such attacks.
Affected Version(s)
Colibri Page Builder * <= 1.0.262