CVE-2025-9560

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Colibri Page Builder adds drag and drop page builder functionality to the ColibriWP theme.</p> <h3>License</h3> <p>Unless otherwise specified, all the theme files and scripts are licensed under GNU General Public License.<br /> The exceptions to this license are as follows:</p> <p>The exceptions to this license are as follows:</p> <ul> <li> <p>bem-sass &#8211; https://github.com/jaeseungyum/bem-sass<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>blob-util &#8211; https://github.com/nolanlawson/blob-util#readme<br /> Licensed under the Apache-2.0 license (https://www.apache.org/licenses/LICENSE-2.0)</p> </li> <li> <p>clean-deep &#8211; https://github.com/nunofgs/clean-deep<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>desandro-matches-selector &#8211;<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>domready &#8211; https://github.com/ded/domready<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>ev-emitter &#8211; https://github.com/metafizzy/ev-emitter#readme<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>outlayer &#8211; https://github.com/metafizzy/outlayer<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>vue-directive-tooltip &#8211; https://github.com/hekigan/vue-directive-tooltip#readme<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>vue-svgicon &#8211; https://github.com/MMF-FE/vue-svgicon#readme<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>Ionicons &#8211; https://ionicons.com<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>Icon by Font Awesome (https://fontawesome.com)<br /> Licensed under the CC BY 4.0 license (https://fontawesome.com/license/free)</p> </li> <li> <p>Icons8 Line Awesome (https://github.com/icons8/line-awesome)<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>Kube.CSS &amp; JS Framework &#8211; http://imperavi.com/kube/<br /> Copyright (c) 2009-2017, Imperavi LLC.<br /> Licensed under the MIT license (https://opensource.org/licenses/MIT)</p> </li> <li> <p>Framework &#8211; Bootstrap<br /> Licensed Under MIT license ( https://opensource.org/licenses/MIT)</p> </li> <li> <p>axios &#8211; https://github.com/axios/axios<br /> Licensed under the MIT license (https://github.com/axios/axios/raw/master/LICENSE)</p> </li> <li> <p>bem-cn &#8211; https://github.com/albburtsev/bem-cn<br /> Licensed under the MIT license (https://github.com/albburtsev/bem-cn/raw/master/LICENSE)</p> </li> <li> <p>blob-util &#8211; https://github.com/nolanlawson/blob-util<br /> Licensed under the Apache-2.0 license (https://github.com/nolanlawson/blob-util/raw/master/LICENSE)</p> </li> <li> <p>change-case &#8211; https://github.com/blakeembrey/change-case<br /> Licensed under the MIT license (https://github.com/blakeembrey/change-case/raw/master/LICENSE)</p> </li> <li> <p>clean-deep &#8211; https://github.com/nunofgs/clean-deep<br /> Licensed under the MIT license (https://github.com/nunofgs/clean-deep/raw/master/LICENSE)</p> </li> <li> <p>countup.js &#8211; https://github.com/inorganik/countUp.js<br /> Licensed under the MIT license (https://github.com/inorganik/countUp.js/raw/master/LICENSE.md)</p> </li> <li> <p>countup &#8211; https://github.com/inorganik/countUp.js<br /> Licensed under the MIT license (https://github.com/inorganik/countUp.js/raw/master/LICENSE.md)</p> </li> <li> <p>cssobj-core &#8211; https://github.com/cssobj/cssobj-core<br /> Licensed under the MIT license (https://github.com/cssobj/cssobj-core)</p> </li> <li> <p>cssobj-plugin-cssom &#8211; https://github.com/cssobj/cssobj-plugin-cssom<br /> Licensed under the MIT license (https://github.com/cssobj/cssobj-plugin-cssom)</p> </li> <li> <p>deepdash-es &#8211; https://github.com/YuriGor/deepdash<br /> Licensed under the MIT license (https://github.com/YuriGor/deepdash)</p> </li> <li> <p>dnd-core &#8211; https://github.com/react-dnd/react-dnd<br /> Licensed under the BSD-3-Clause license (https://github.com/react-dnd/react-dnd/raw/master/LICENSE)</p> </li> <li> <p>dragula &#8211; https://github.com/bevacqua/dragula<br /> Licensed under the MIT license (https://github.com/bevacqua/dragula/raw/master/license)</p> </li> <li> <p>element-ui &#8211; https://github.com/ElemeFE/element<br /> Licensed under the MIT license (https://github.com/ElemeFE/element/raw/master/LICENSE)</p> </li> <li> <p>escape-string-regexp &#8211; https://github.com/sindresorhus/escape-string-regexp<br /> Licensed under the MIT license (https://github.com/sindresorhus/escape-string-regexp/raw/master/license)</p> </li> <li> <p>eslint-config-airbnb &#8211; https://github.com/airbnb/javascript<br /> Licensed under the MIT license (https://github.com/airbnb/javascript/raw/master/LICENSE.md)</p> </li> <li> <p>firebase-firestore-fields &#8211; https://github.com/invertase/firebase-firestore-fields<br /> Licensed under the APACHE-2.0 license (https://github.com/invertase/firebase-firestore-fields/raw/master/LICENSE)</p> </li> <li> <p>firebase &#8211; https://github.com/firebase/firebase-js-sdk<br /> Licensed under the Apache-2.0 license (https://github.com/firebase/firebase-js-sdk)</p> </li> <li> <p>firebaseui &#8211; https://github.com/firebase/firebaseui-web<br /> Licensed under the Apache-2.0 license (https://github.com/firebase/firebaseui-web/raw/master/LICENSE)</p> </li> <li> <p>fuse.js &#8211; https://github.com/krisk/Fuse<br /> Licensed under the Apache license (https://github.com/krisk/Fuse/raw/master/LICENSE)</p> </li> <li> <p>get-urls &#8211; https://github.com/sindresorhus/get-urls<br /> Licensed under the MIT license (https://github.com/sindresorhus/get-urls/raw/master/license)</p> </li> <li> <p>glob &#8211; https://github.com/isaacs/node-glob<br /> Licensed under the ISC license (https://github.com/isaacs/node-glob/raw/master/LICENSE)</p> </li> <li> <p>hotkeys-js &#8211; https://github.com/jaywcjlove/hotkeys<br /> Licensed under the MIT license (https://github.com/jaywcjlove/hotkeys/raw/master/LICENSE)</p> </li> <li> <p>html2canvas &#8211; https://github.com/niklasvh/html2canvas<br /> Licensed under the MIT license (https://github.com/niklasvh/html2canvas/raw/master/LICENSE)</p> </li> <li> <p>is-image-url &#8211; https://github.com/wzbg/is-image-url<br /> Licensed under the MIT license (https://github.com/wzbg/is-image-url/raw/master/LICENSE)</p> </li> <li> <p>jquery-animated-headlines &#8211; https://github.com/GeoffSelby/jquery-animated-headlines<br /> Licensed under the MIT license (https://github.com/GeoffSelby/jquery-animated-headlines)</p> </li> <li> <p>jquery-circle-progress &#8211; https://github.com/kottenator/jquery-circle-progress<br /> Licensed under the MIT license (https://github.com/kottenator/jquery-circle-progress/raw/master/LICENSE)</p> </li> <li> <p>jquery-easing &#8211; https://github.com/viskin/jquery-easing<br /> Licensed under the LicenseRef-LICENSE license (https://github.com/viskin/jquery-easing/raw/master/LICENSE)</p> </li> <li> <p>jsdom-global &#8211; https://github.com/rstacruz/jsdom-global<br /> Licensed under the MIT license (https://github.com/rstacruz/jsdom-global)</p> </li> <li> <p>jsdom &#8211; https://github.com/jsdom/jsdom<br /> Licensed under the MIT license (https://github.com/jsdom/jsdom/raw/master/LICENSE.txt)</p> </li> <li> <p>jsondiffpatch &#8211; https://github.com/benjamine/jsondiffpatch<br /> Licensed under the MIT license (https://github.com/benjamine/jsondiffpatch)</p> </li> <li> <p>jump.js &#8211; https://github.com/callmecavs/jump.js<br /> Licensed under the MIT license (https://github.com/callmecavs/jump.js)</p> </li> <li> <p>lodash.debounce &#8211; https://github.com/lodash/lodash<br /> Licensed under the MIT license (https://github.com/lodash/lodash/raw/master/LICENSE)</p> </li> <li> <p>lodash &#8211; https://github.com/lodash/lodash<br /> Licensed under the MIT license (https://github.com/lodash/lodash/raw/master/LICENSE)</p> </li> <li> <p>masonry-layout &#8211; https://github.com/desandro/masonry<br /> Licensed under the MIT license (https://github.com/desandro/masonry)</p> </li> <li> <p>nouislider &#8211; https://github.com/leongersen/noUiSlider<br /> Licensed under the WTFPL license (https://github.com/leongersen/noUiSlider/raw/master/LICENSE)</p> </li> <li> <p>npm-license-crawler &#8211; https://github.com/mwittig/npm-license-crawler<br /> Licensed under the BSD-3-Clause license (https://github.com/mwittig/npm-license-crawler/raw/master/LICENSE)</p> </li> <li> <p>npm &#8211; https://github.com/npm/cli<br /> Licensed under the Artistic-2.0 license (https://github.com/npm/cli/raw/master/.licensee.json)</p> </li> <li> <p>pako &#8211; https://github.com/nodeca/pako<br /> Licensed under the (MIT AND Zlib) license (https://github.com/nodeca/pako/raw/master/LICENSE)</p> </li> <li> <p>popper.js &#8211; https://github.com/FezVrasta/popper.js<br /> Licensed under the MIT license (https://github.com/FezVrasta/popper.js)</p> </li> <li> <p>postcss-js &#8211; https://github.com/postcss/postcss-js<br /> Licensed under the MIT license (https://github.com/postcss/postcss-js/raw/master/LICENSE)</p> </li> <li> <p>postcss &#8211; https://github.com/postcss/postcss<br /> Licensed under the MIT license (https://github.com/postcss/postcss/raw/master/LICENSE)</p> </li> <li> <p>pretty &#8211; https://github.com/jonschlinkert/pretty<br /> Licensed under the MIT license (https://github.com/jonschlinkert/pretty/raw/master/LICENSE)</p> </li> <li> <p>react-dnd-html5-backend &#8211; https://github.com/react-dnd/react-dnd<br /> Licensed under the BSD-3-Clause license (https://github.com/react-dnd/react-dnd/raw/master/LICENSE)</p> </li> <li> <p>shortcode-insert &#8211; https://github.com/whitebolt/shortcode-insert<br /> Licensed under the MIT license (https://github.com/whitebolt/shortcode-insert/raw/master/LICENCE.md)</p> </li> <li> <p>sortablejs &#8211; https://github.com/SortableJS/Sortable<br /> Licensed under the MIT license (https://github.com/SortableJS/Sortable)</p> </li> <li> <p>speakingurl &#8211; https://github.com/pid/speakingurl<br /> Licensed under the BSD-3-Clause license (https://github.com/pid/speakingurl/raw/master/LICENSE)</p> </li> <li> <p>string-template-parser &#8211; https://github.com/souldreamer/string-template-parser<br /> Licensed under the MIT license (https://github.com/souldreamer/string-template-parser)</p> </li> <li> <p>swiper &#8211; https://github.com/nolimits4web/Swiper<br /> Licensed under the MIT license (https://github.com/nolimits4web/Swiper/raw/master/LICENSE)</p> </li> <li> <p>tinycolor2 &#8211; https://bgrinshub.com/TinyColor<br /> Licensed under the MIT license (https://bgrinshub.com/TinyColor)</p> </li> <li> <p>to-css &#8211; https://github.com/joakimbeng/to-css<br /> Licensed under the MIT license (https://github.com/joakimbeng/to-css)</p> </li> <li> <p>to-px &#8211; https://github.com/mikolalysenko/to-px<br /> Licensed under the MIT license (https://github.com/mikolalysenko/to-px/raw/master/LICENSE)</p> </li> <li> <p>v-click-outside &#8211; https://github.com/ndelvalle/v-click-outside<br /> Licensed under the MIT license (https://github.com/ndelvalle/v-click-outside/raw/master/LICENSE)</p> </li> <li> <p>v-hotkey &#8211; https://github.com/Dafrok/v-hotkey<br /> Licensed under the MIT license (https://github.com/Dafrok/v-hotkey/raw/master/LICENSE)</p> </li> <li> <p>vue-async-computed &#8211; https://github.com/foxbenjaminfox/vue-async-computed<br /> Licensed under the MIT license (https://github.com/foxbenjaminfox/vue-async-computed/raw/master/LICENSE)</p> </li> <li> <p>vue-awesome-swiper &#8211; https://github.com/surmon-china/vue-awesome-swiper<br /> Licensed under the MIT license (https://github.com/surmon-china/vue-awesome-swiper/raw/master/LICENSE)</p> </li> <li> <p>vue-bem-cn &#8211; https://github.com/c01nd01r/vue-bem-cn<br /> Licensed under the MIT license (https://github.com/c01nd01r/vue-bem-cn/raw/master/LICENSE)</p> </li> <li> <p>vue-clickaway &#8211; https://github.com/simplesmiler/vue-clickaway<br /> Licensed under the MIT license (https://github.com/simplesmiler/vue-clickaway/raw/master/LICENSE)</p> </li> <li> <p>vue-context-menu &#8211; https://github.com/vmaimone/vue-context-menu<br /> Licensed under the ISC license (https://github.com/vmaimone/vue-context-menu)</p> </li> <li> <p>vue-context &#8211; https://github.com/rawilk/vue-context<br /> Licensed under the MIT license (https://github.com/rawilk/vue-context/raw/master/LICENSE)</p> </li> <li> <p>vue-count-to<br /> Licensed under the MIT license (http://panjiachen.github.io/countTo/demo/)</p> </li> <li> <p>vue-countup-v2 &#8211; https://github.com/xlsdg/vue-countup-v2<br /> Licensed under the MIT license (https://github.com/xlsdg/vue-countup-v2/raw/master/LICENSE)</p> </li> <li> <p>vue-firestore<br /> Licensed under the MIT license</p> </li> <li> <p>vue-fraction-grid &#8211; https://github.com/bkzl/vue-fraction-grid<br /> Licensed under the MIT license (https://github.com/bkzl/vue-fraction-grid/raw/master/LICENSE)</p> </li> <li> <p>vue-free-transform &#8211; https://github.com/skmail/vue-free-transform<br /> Licensed under the MIT* license (https://github.com/skmail/vue-free-transform/raw/master/LICENSE.md)</p> </li> <li> <p>vue-hoc &#8211; https://github.com/jackmellis/vue-hoc<br /> Licensed under the Apache-2.0 license (https://github.com/jackmellis/vue-hoc/raw/master/LICENSE)</p> </li> <li> <p>vue-localstorage &#8211; https://github.com/pinguinjkeke/vue-local-storage<br /> Licensed under the MIT license (https://github.com/pinguinjkeke/vue-local-storage/raw/master/LICENSE)</p> </li> <li> <p>vue-mutation-observer &#8211; https://github.com/PNKBizz/vue-mutation-observer<br /> Licensed under the MIT license (https://github.com/PNKBizz/vue-mutation-observer)</p> </li> <li> <p>vue-perfect-scrollbar &#8211; https://github.com/Degfy/vue-perfect-scrollbar<br /> Licensed under the MIT license (https://github.com/Degfy/vue-perfect-scrollbar)</p> </li> <li> <p>vue-quill-editor &#8211; https://github.com/surmon-china/vue-quill-editor<br /> Licensed under the MIT license (https://github.com/surmon-china/vue-quill-editor/raw/master/LICENSE)</p> </li> <li> <p>vue-react-dnd &#8211; https://github.com/jenshaase/vue-react-dnd<br /> Licensed under the MIT license (https://github.com/jenshaase/vue-react-dnd/raw/master/LICENSE)</p> </li> <li> <p>vue-scrollto &#8211; https://github.com/rigor789/vue-scrollto<br /> Licensed under the MIT license (https://github.com/rigor789/vue-scrollto/raw/master/LICENSE)</p> </li> <li> <p>vue-shortkey &#8211; https://github.com/iFgR/vue-shortkey<br /> Licensed under the MIT license (https://github.com/iFgR/vue-shortkey/raw/master/LICENSE)</p> </li> <li> <p>vue-slider-component &#8211; https://github.com/NightCatSama/vue-slider-component<br /> Licensed under the MIT license (https://github.com/NightCatSama/vue-slider-component/raw/master/LICENSE)</p> </li> <li> <p>vue-sortable &#8211; https://github.com/sagalbot/vue-sortable<br /> Licensed under the MIT license (https://github.com/sagalbot/vue-sortable/raw/master/LICENSE.md)</p> </li> <li> <p>vue-videobg &#8211; https://github.com/pespantelis/vue-videobg<br /> Licensed under the MIT license (https://github.com/pespantelis/vue-videobg/raw/master/LICENSE)</p> </li> <li> <p>vue-virtual-collection &#8211; https://github.com/starkwang/vue-virtual-collection<br /> Licensed under the MIT license (https://github.com/starkwang/vue-virtual-collection/raw/master/LICENSE)</p> </li> <li> <p>vue &#8211; https://github.com/vuejs/vue<br /> Licensed under the MIT license (https://github.com/vuejs/vue/raw/master/LICENSE)</p> </li> <li> <p>vuefire &#8211; https://github.com/vuejs/vuefire<br /> Licensed under the MIT license (https://github.com/vuejs/vuefire/raw/master/LICENSE)</p> </li> <li> <p>vuex-persist &#8211; https://github.com/championswimmer/vuex-persist<br /> Licensed under the MIT license (https://github.com/championswimmer/vuex-persist/raw/master/LICENSE.md)</p> </li> <li> <p>vuex &#8211; https://github.com/vuejs/vuex<br /> Licensed under the MIT license (https://github.com/vuejs/vuex/raw/master/LICENSE)</p> </li> <li> <p>webfontloader &#8211; https://github.com/typekit/webfontloader<br /> Licensed under the Apache-2.0 license (https://github.com/typekit/webfontloader/raw/master/LICENSE)</p> </li> <li> <p>extend-builder/assets/images/x-header-default.jpg<br /> Source: https://www.maxpixel.net/Wave-Abstract-Pattern-Lines-Movement-Swing-1500063<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/1.jpg<br /> Source: https://stocksnap.io/photo/RMOCSAQNUG<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/2.jpg<br /> Source: https://stocksnap.io/photo/Y8OHDLLUN1<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/3.jpg<br /> Source: https://pxhere.com/en/photo/1432895<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/4.jpg<br /> Source: https://stocksnap.io/photo/LPZFCLQN45<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/5.jpg<br /> Source: https://stocksnap.io/photo/UDWZ9OZ6QQ<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/6.jpg<br /> Source: https://pxhere.com/en/photo/1592854<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/7.jpg<br /> Source: https://pxhere.com/en/photo/1427195<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/8.jpg<br /> Source: https://stocksnap.io/photo/96DA9Q241I<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-1.jpg<br /> Source: https://stocksnap.io/photo/96DA9Q241I<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-2.jpg<br /> Source: https://pxhere.com/en/photo/1427195<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-3.jpg<br /> Source: https://stocksnap.io/photo/Y8OHDLLUN1<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-4.jpg<br /> Source: https://pxhere.com/en/photo/1432895<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-5.jpg<br /> Source: https://stocksnap.io/photo/RMOCSAQNUG<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-6.jpg<br /> Source: https://stocksnap.io/photo/UDWZ9OZ6QQ<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <li> <p>extend-builder/assets/images/masonry-7.jpg<br /> Source: https://pxhere.com/en/photo/1592854<br /> Licensed under Creative Commons Zero license, http://creativecommons.org/publicdomain/zero/1.0/</p> </li> <l
WordPress Plugin DirectoryWordPress Plugin Directory
3.92M