CVE-2024-1870: Colibri Page Builder <= 1.0.260 - Missing Authorization
The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1870?
CVE-2024-1870 is considered a medium severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-1870?
To fix CVE-2024-1870, update the Colibri Page Builder plugin to version 1.0.261 or later.
What does CVE-2024-1870 affect?
CVE-2024-1870 affects the Colibri Page Builder plugin for WordPress, specifically versions up to and including 1.0.260.
Who can exploit CVE-2024-1870?
Authenticated attackers with subscriber access or higher can exploit CVE-2024-1870 to modify data.
What is the main issue caused by CVE-2024-1870?
The main issue caused by CVE-2024-1870 is the lack of a capability check in the callActivateLicenseEndpoint function, leading to unauthorized modifications.