WPBakery Page Builder Clipboard < 4.5.8 - Arbitrary License Options Update

Strategic Overview

Status
Patched in 4.5.8
Affected Version< 4.5.8
CVSS6.5Medium
CVECVE-2021-24244
View all WPBakery Page Builder Clipboard vulnerabilities

Vulnerability Overview

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

Technical Analysis

REMEDIATION: Update to version 4.5.8, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C