Stored Cross-Site Scripting in Colibri Page Builder Plugin for WordPress
CVE-2025-11747
What is CVE-2025-11747?
The Colibri Page Builder plugin, utilized in WordPress, is prone to a Stored Cross-Site Scripting vulnerability through the colibri_blog_posts shortcode. This issue arises from inadequate input sanitization and escape output processes concerning user-supplied attributes. As a result, authenticated users with contributor-level access or higher can inject malicious scripts into affected webpages. When other users access these compromised pages, the injected scripts will execute, compromising the site's security and potentially leading to data theft, session hijacking, or further exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Colibri Page Builder * <= 1.0.345
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved