Stored Cross-Site Scripting Vulnerability in Colibri Page Builder Plugin for WordPress
CVE-2024-3338
5.4MEDIUM
Summary
The Colibri Page Builder plugin for WordPress has a vulnerability that allows authenticated attackers with author-level access or higher to execute arbitrary web scripts. This is due to inadequate sanitization of the image alt data parameter, which can lead to Stored Cross-Site Scripting attacks. When a user visits an infected page, the injected scripts can execute, potentially compromising user data and website integrity. Immediate remediation and updating are essential to safeguard against such attacks.
Affected Version(s)
Colibri Page Builder * <= 1.0.262
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings