Web and WooCommerce Addons for WPBakery Builder <= 1.4.4.1 - Missing Authorization Checks

2022-07-06 00:00
Anonymous

Strategic Overview

Vulnerability Overview

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the AJAX actions and modify the plugins settings along with injecting malicious web scripts.

Technical Analysis

REMEDIATION: Update to version 1.4.4.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C