WPBakery Page Builder Clipboard < 4.5.8 - Unauthorised Arbitrary License Options Update
Vulnerability Description
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24244
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Charles Strader Sweethill
References
Affected Vendor
bitorbit
View all reports →