Ninja Beaver Add-ons for Beaver Builder [ninja-beaver-lite-addons-for-beaver-builder] <= 2.4.5 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This issue affects Ninja Beaver Add-ons for Beaver Builder: from n/a through 2.4.5.
- Affected:
- up to 2.4.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2024
CVE-2024-37244 on NVD →
Ninja Beaver Add-ons for Beaver Builder [ninja-beaver-lite-addons-for-beaver-builder] <= 2.4.5 (unfixed + closed)
unknown
[en] The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping on user supplied attributes such as urls. This makes it possible for authenti...
- Affected:
- up to 2.4.5
- Fix:
- No patched version reported
- Disclosed:
- May 22, 2024
CVE-2024-2163 on NVD →
Ninja Beaver Add-ons for Beaver Builder <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widgets
medium
The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping on user supplied attributes such as urls. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 2.4.5
- Fix:
- No patched version reported
- Disclosed:
- May 21, 2024
CVE-2024-2163 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database