Vulnerability Details CVE-2024-2839
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, 1.0.263 due to insufficient input sanitization and output escaping on user supplied attributes such as 'heading_type'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 6.4
Products affected by CVE-2024-2839
-
cpe:2.3:a:extendthemes:colibri_page_builder:-
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.130
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.145
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.165
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.173
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.175
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.177
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.178
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.179
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.180
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.182
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.185
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.186
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.188
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.190
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.191
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.192
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.198
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.202
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.206
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.208
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.209
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.210
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.211
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.216
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.221
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.222
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.223
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.227
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.229
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.232
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.236
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.239
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.240
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.241
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.246
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.248
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.249
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.253
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.260
-
cpe:2.3:a:extendthemes:colibri_page_builder:1.0.263