CVE-2023-50833: WordPress Colibri Page Builder Plugin <= 1.0.239 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExtendThemes Colibri Page Builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through 1.0.239.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50833?
CVE-2023-50833 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2023-50833?
To fix CVE-2023-50833, upgrade the ExtendThemes Colibri Page Builder to version 1.0.240 or later.
What software versions are affected by CVE-2023-50833?
CVE-2023-50833 affects ExtendThemes Colibri Page Builder versions up to and including 1.0.239.
What is Cross-site Scripting in relation to CVE-2023-50833?
Cross-site Scripting (XSS) in CVE-2023-50833 refers to the improper neutralization of input that allows attackers to inject malicious scripts into webpages.
Can I exploit CVE-2023-50833 to gain unauthorized access?
Yes, exploiting CVE-2023-50833 can allow attackers to execute scripts in the context of user sessions, potentially leading to unauthorized access.