plugin

Bb Ultimate Addon Vulnerabilities

9 known security issues reported for the Bb Ultimate Addon WordPress plugin. Most recent disclosed May 17, 2024.

1 critical 1 high 1 medium

Running Bb Ultimate Addon on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.35.15

unknown

[en] Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.

Affected:
up to 1.35.15
Fixed in:
1.35.15
Disclosed:
May 17, 2024

CVE-2023-51398 on NVD →

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.35.14

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.

Affected:
up to 1.35.14
Fixed in:
1.35.14
Disclosed:
May 17, 2024

CVE-2023-51401 on NVD →

Ultimate Addons for Beaver Builder <= 1.35.14 - Authenticated(Contributor+) Privilege Escalation

high

The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.35.14. This makes it possible for authenticated attackers, with contributor access and above, to escalate their privileges to those of a higher level user.

CVSS:
8.8
Affected:
up to 1.35.14
Fixed in:
1.35.15
Disclosed:
Dec 26, 2023

CVE-2023-51398 on NVD →

Ultimate Addons for Beaver Builder <= 1.35.13 - Authenticated(Contributor+) Directory Traversal to Arbitrary File Download

medium

The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.35.13. This makes it possible for authenticated attackers, with Contributor access and above, to read the contents of a limited subset of arbitrary files on the server, which can cont...

CVSS:
4.3
Affected:
up to 1.35.13
Fixed in:
1.35.14
Disclosed:
Dec 26, 2023

CVE-2023-51401 on NVD →

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.25.0

unknown

Cross-Site Scripting (XSS) vulnerability discovered in WordPress Ultimate Addons for Beaver Builder (versions <= 1.24.3).

Affected:
up to 1.25.0
Fixed in:
1.25.0
Disclosed:
Jan 22, 2020

Ultimate Addons for Beaver Builder <= 1.24.0 - Authentication Bypass

critical

The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the get-google-data() and get-facebook-data() functions in versions up to, and including, 1.24.0. This makes it possible for unauthorized attackers to log into any account on the associa...

CVSS:
9.8
Affected:
up to 1.24.0
Fixed in:
1.24.1
Disclosed:
Dec 12, 2019

CVE-2019-25763 on NVD →

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1

unknown

Authentication Bypass vulnerability found by MalCare in WordPress Ultimate Addons for Beaver Builder plugin (versions <= 1.24.0).

Affected:
up to 1.24.1
Fixed in:
1.24.1
Disclosed:
Dec 12, 2019

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1

unknown

The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the get-google-data() and get-facebook-data() functions in versions up to, and including, 1.24.0. This makes it possible for unauthorized attackers to log into any account on the associa...

Affected:
up to 1.24.1
Fixed in:
1.24.1
Disclosed:
Dec 12, 2019

Ultimate Addons for Beaver Builder [bb-ultimate-addon] < 1.24.1

unknown
Affected:
up to 1.24.1
Fixed in:
1.24.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database