What the vulnerability does
01Description
Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.
Explanation of Vulnerability in Simple Terms
Colibri Page Builder versions up to 1.0.248 lack proper authorization checks, allowing authenticated users to modify site content and settings they should not have access to. An attacker with low-level account privileges can alter page data and availability without proper permission validation. This affects the integrity and availability of published pages.
What an attacker can do
Modify or disable pages and site settings despite lacking authorization to do so.
Potential impact on your site
Unauthorized users can alter or disable published pages, disrupting site content and user experience.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities