Stored Cross-Site Scripting Vulnerability in Colibri Page Builder Plugin for WordPress
CVE-2024-3338
5.4MEDIUM
What is CVE-2024-3338?
The Colibri Page Builder plugin for WordPress has a vulnerability that allows authenticated attackers with author-level access or higher to execute arbitrary web scripts. This is due to inadequate sanitization of the image alt data parameter, which can lead to Stored Cross-Site Scripting attacks. When a user visits an infected page, the injected scripts can execute, potentially compromising user data and website integrity. Immediate remediation and updating are essential to safeguard against such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Colibri Page Builder * <= 1.0.262
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings