Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.35.15
unknown
[en] Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.
- Affected:
- up to 1.35.15
- Fixed in:
- 1.35.15
- Disclosed:
- May 17, 2024
CVE-2023-51398 on NVD →
Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.35.14
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.
- Affected:
- up to 1.35.14
- Fixed in:
- 1.35.14
- Disclosed:
- May 17, 2024
CVE-2023-51401 on NVD →
Ultimate Addons for Beaver Builder <= 1.35.14 - Authenticated(Contributor+) Privilege Escalation
high
The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.35.14. This makes it possible for authenticated attackers, with contributor access and above, to escalate their privileges to those of a higher level user.
- CVSS:
- 8.8
- Affected:
- up to 1.35.14
- Fixed in:
- 1.35.15
- Disclosed:
- Dec 26, 2023
CVE-2023-51398 on NVD →
Ultimate Addons for Beaver Builder <= 1.35.13 - Authenticated(Contributor+) Directory Traversal to Arbitrary File Download
medium
The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.35.13. This makes it possible for authenticated attackers, with Contributor access and above, to read the contents of a limited subset of arbitrary files on the server, which can cont...
- CVSS:
- 4.3
- Affected:
- up to 1.35.13
- Fixed in:
- 1.35.14
- Disclosed:
- Dec 26, 2023
CVE-2023-51401 on NVD →
Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.25.0
unknown
Cross-Site Scripting (XSS) vulnerability discovered in WordPress Ultimate Addons for Beaver Builder (versions <= 1.24.3).
- Affected:
- up to 1.25.0
- Fixed in:
- 1.25.0
- Disclosed:
- Jan 22, 2020
Ultimate Addons for Beaver Builder <= 1.24.0 - Authentication Bypass
critical
The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the get-google-data() and get-facebook-data() functions in versions up to, and including, 1.24.0. This makes it possible for unauthorized attackers to log into any account on the associa...
- CVSS:
- 9.8
- Affected:
- up to 1.24.0
- Fixed in:
- 1.24.1
- Disclosed:
- Dec 12, 2019
CVE-2019-25763 on NVD →
Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1
unknown
Authentication Bypass vulnerability found by MalCare in WordPress Ultimate Addons for Beaver Builder plugin (versions <= 1.24.0).
- Affected:
- up to 1.24.1
- Fixed in:
- 1.24.1
- Disclosed:
- Dec 12, 2019
Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1
unknown
The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the get-google-data() and get-facebook-data() functions in versions up to, and including, 1.24.0. This makes it possible for unauthorized attackers to log into any account on the associa...
- Affected:
- up to 1.24.1
- Fixed in:
- 1.24.1
- Disclosed:
- Dec 12, 2019
Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1
unknown
- Affected:
- up to 1.24.1
- Fixed in:
- 1.24.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database