CVE-2024-28004: WordPress Colibri Page Builder plugin <= 1.0.248 - Broken Access Control vulnerability
Published Mar 28, 2024
·Updated
Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.
Affected Software
3 affected components
ExtendThemes Colibri Page Builder Wordpress<1.0.249
ExtendThemes Colibri Page Builder<=1.0.248
WordPress Colibri Page Builder<=1.0.248
Remediation
Information
Update to 1.0.249 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:51 AM
Data Sourced
via MITRE·05:51 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28004?
CVE-2024-28004 is classified as a Missing Authorization vulnerability and has a medium severity level.
2
How do I fix CVE-2024-28004?
To mitigate CVE-2024-28004, update ExtendThemes Colibri Page Builder to version 1.0.249 or later.
3
What versions of Colibri Page Builder are affected by CVE-2024-28004?
CVE-2024-28004 affects all versions of Colibri Page Builder from n/a up to and including version 1.0.248.
4
What type of vulnerability is CVE-2024-28004?
CVE-2024-28004 is identified as a Missing Authorization vulnerability.
5
Who is the vendor for CVE-2024-28004?
The vendor for CVE-2024-28004 is ExtendThemes.