CVE-2021-24243
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
- Affected products
- Wpbakery Page Builder (Visual Composer) Clipboard
- Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard
- < 4.5.6
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-05-05
CVE-2021-24243 at NVD
1 known exploit for CVE-2021-24243
Proof-of-concept code and exploit modules indexed by Sploitus