Vulnerability Details CVE-2024-1362
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to missing or incorrect nonce validation on the cp_shortcode_refresh() function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-1362
-
cpe:2.3:a:extendthemes:colibri_page_builder:-
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.130
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.145
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.165
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.173
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.175
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.177
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.178
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.179
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.180
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.182
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.185
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.186
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.188
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.190
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.191
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.192
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.198
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.202
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.206
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.208
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.209
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.210
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.211
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.216
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.221
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.222
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.223
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.227
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.229
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.232
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.236
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.239
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.240
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.241
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.246
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.248
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.249
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.253