Cross-site Scripting Risk in Extend Themes Colibri Page Builder
CVE-2025-59593

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-59593?

The Extend Themes Colibri Page Builder has a vulnerability that leads to stored Cross-site Scripting (XSS) attacks due to improper input neutralization during web page generation. This issue could allow attackers to inject malicious scripts that are executed when users visit affected pages, potentially compromising user data and site integrity.

Affected Version(s)

Colibri Page Builder <= n/a

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

savphill (Patchstack Alliance)
.