| |
Vulnerability CVE-2021-24244
Published: 2021-05-06
Description: |
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email). |
Type:
CWE-863 (Incorrect Authorization)
CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
https://wpscan.com/vulnerability/354b98d8-46a1-4189-b347-198701ea59b9
https://codecanyon.net/item/visual-composer-clipboard/8897711
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|