Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.10
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.9.
- Affected:
- up to 1.5.10
- Fixed in:
- 1.5.10
- Disclosed:
- Aug 12, 2024
CVE-2024-43151 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbit...
- CVSS:
- 6.4
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.10
- Disclosed:
- Aug 7, 2024
CVE-2024-43151 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8
unknown
[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 30, 2024
CVE-2024-2140 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8
unknown
[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 30, 2024
CVE-2024-2142 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8
unknown
[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 30, 2024
CVE-2024-2143 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8
unknown
[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 30, 2024
CVE-2024-2144 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8
unknown
[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level ac...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 30, 2024
CVE-2024-2141 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 29, 2024
CVE-2024-2141 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Widget
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 29, 2024
CVE-2024-2143 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Icons Widget
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 29, 2024
CVE-2024-2140 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Table Widget
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acc...
- CVSS:
- 6.4
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 29, 2024
CVE-2024-2142 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Separator Widget
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...
- CVSS:
- 6.4
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Mar 29, 2024
CVE-2024-2144 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.6
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5.
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jan 17, 2024
CVE-2023-23882 on NVD →
Ultimate Addons for Beaver Builder - Lite <= 1.5.5 - Authenticated (Subscriber+) Settings Change
medium
The Ultimate Addons for Beaver Builder - Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce check on the 'fetch_cloud_templates' function in versions up to, and including, 1.5.5. This makes it possible for subscriber-level attackers to refresh the plugin's cloud templa...
- CVSS:
- 4.3
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.6
- Disclosed:
- Jan 24, 2023
CVE-2023-23882 on NVD →
Ultimate Addons for Beaver Builder – Lite <= 1.5.4 - Missing Authorization
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 1.5.4. This is due to missing capability on the reload_icons function. This makes it possible for authenticated attackers, with subscriber-level access to delete the '_uabb_enabled_...
- CVSS:
- 5.4
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Jan 23, 2023
Ultimate Addons for Beaver Builder – Lite <= 1.5.4 - Cross-Site Request Forgery
medium
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the reload_icons function. This makes it possible for unauthenticated attackers to invoke this function leading...
- CVSS:
- 5.4
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Jan 23, 2023
CVE-2023-23882 on NVD →
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.5
unknown
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 1.5.4. This is due to missing capability on the reload_icons function. This makes it possible for authenticated attackers, with subscriber-level access to delete the '_uabb_enabled_...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jan 23, 2023
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.5
unknown
The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the reload_icons function. This makes it possible for unauthenticated attackers to invoke this function leading...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jan 23, 2023
Ultimate Addons for Beaver Builder – Lite [ultimate-addons-for-beaver-builder-lite] < 1.25.0
unknown
From the plugin's changelog file:
"22 Jan 2020
Important Security Update: Update Now!
A security researcher privately reported a bug about cross-site scripting (XSS) vulnerability. Our team immediately took action, and provided the required patch within 2 hours, releasing the update on the same day a...
- Affected:
- up to 1.25.0
- Fixed in:
- 1.25.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database