ZeroHour

CVE-2021-24243

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

Vendors
wpbakery page builder clipboard project
Products
wpbakery page builder clipboard
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.