CVE-2023-1274
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p58
Published
()
Modified
Description
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
- Vendors
- pricing tables for wpbakery page builder project
- Products
- pricing tables for wpbakery page builder
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.