The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jan 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Extendthemes
Extendthemes colibri Page Builder |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:extendthemes:colibri_page_builder:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Extendthemes
Extendthemes colibri Page Builder |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-09T09:37:46.628Z
Updated: 2024-08-01T18:56:22.387Z
Reserved: 2024-02-23T21:59:45.320Z
Link: CVE-2024-1870

Updated: 2024-08-01T18:56:22.387Z

Status : Analyzed
Published: 2024-03-09T10:15:06.370
Modified: 2025-01-28T18:13:19.037
Link: CVE-2024-1870

No data.