Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension <= 3.1.2 - Authenticated Arbitrary Options Update
2022-07-25 00:00
R3N0Strategic Overview
StatusPatched in 3.2.0
Affected Version
<= 3.1.2CVSS7.2High
CVE
CVE-2022-33970Vulnerability Overview
The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 3.1.2. This makes it possible for authenticated attackers to modify arbitrary site options that can be used for complete site takeover.
Technical Analysis
REMEDIATION: Update to version 3.2.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C