CVE-2025-32185: WordPress Colibri Page Builder plugin <= 1.0.329 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through <= 1.0.329.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32185?
CVE-2025-32185 is considered a medium severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-32185?
To fix CVE-2025-32185, update the Colibri Page Builder plugin to version 1.0.320 or above.
What do I need to know about the impact of CVE-2025-32185?
CVE-2025-32185 can allow attackers to execute malicious scripts in the context of the user's browser, potentially compromising user data.
Who is affected by CVE-2025-32185?
CVE-2025-32185 affects all versions of the Extend Themes Colibri Page Builder up to and including 1.0.319.
Are there any workarounds for CVE-2025-32185?
There are no recommended workarounds for CVE-2025-32185; updating to a fixed version is the best course of action.