Sploitus

CVE-2021-24243

1 known exploit for CVE-2021-24243

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard
< 4.5.6
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.7% (51th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-05-05
CVE-2021-24243 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24243

Proof-of-concept code and exploit modules indexed by Sploitus