Stored Cross-Site Scripting in Colibri Page Builder Plugin for WordPress
CVE-2025-11376
6.4MEDIUM
What is CVE-2025-11376?
The Colibri Page Builder plugin for WordPress has a vulnerability that allows authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. This occurs due to inadequate input sanitization and output escaping on attributes supplied by users through the 'colibri_loop' shortcode. Consequently, attackers can inject malicious scripts that execute whenever users visit affected pages, posing significant risks to site integrity and user safety.
Affected Version(s)
Colibri Page Builder * <= 1.0.335