Web and WooCommerce Addons for WPBakery Builder <= 1.4.4.1 - Missing Authorization Checks
2022-07-06 00:00
AnonymousStrategic Overview
StatusPatched in 1.4.4.2
Affected PluginWeb and WooCommerce Addons for WPBakery Builder
Affected Version
<= 1.4.4.1CVSS6.3Medium
CVE
N/AVulnerability Overview
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the AJAX actions and modify the plugins settings along with injecting malicious web scripts.
Technical Analysis
REMEDIATION: Update to version 1.4.4.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C