CVE-2021-24244
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
- Affected products
- Wpbakery Page Builder (Visual Composer) Clipboard
- Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard
- < 4.5.8
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.9% (58th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2021-05-05
CVE-2021-24244 at NVD
1 known exploit for CVE-2021-24244
Proof-of-concept code and exploit modules indexed by Sploitus