plugin

Ultimate Addons For Beaver Builder Lite Vulnerabilities

19 known security issues reported for the Ultimate Addons For Beaver Builder Lite WordPress plugin. Most recent disclosed Aug 12, 2024.

9 medium

Running Ultimate Addons For Beaver Builder Lite on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.10

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.9.

Affected:
up to 1.5.10
Fixed in:
1.5.10
Disclosed:
Aug 12, 2024

CVE-2024-43151 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbit...

CVSS:
6.4
Affected:
up to 1.5.9
Fixed in:
1.5.10
Disclosed:
Aug 7, 2024

CVE-2024-43151 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8

unknown

[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 30, 2024

CVE-2024-2140 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8

unknown

[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 30, 2024

CVE-2024-2142 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8

unknown

[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 30, 2024

CVE-2024-2143 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8

unknown

[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 30, 2024

CVE-2024-2144 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.8

unknown

[en] The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level ac...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Mar 30, 2024

CVE-2024-2141 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Mar 29, 2024

CVE-2024-2141 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Widget

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Mar 29, 2024

CVE-2024-2143 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Icons Widget

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
6.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Mar 29, 2024

CVE-2024-2140 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Table Widget

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acc...

CVSS:
6.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Mar 29, 2024

CVE-2024-2142 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Separator Widget

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

CVSS:
6.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Mar 29, 2024

CVE-2024-2144 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.6

unknown

[en] Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5.

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Jan 17, 2024

CVE-2023-23882 on NVD →

Ultimate Addons for Beaver Builder - Lite <= 1.5.5 - Authenticated (Subscriber+) Settings Change

medium

The Ultimate Addons for Beaver Builder - Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce check on the 'fetch_cloud_templates' function in versions up to, and including, 1.5.5. This makes it possible for subscriber-level attackers to refresh the plugin's cloud templa...

CVSS:
4.3
Affected:
up to 1.5.5
Fixed in:
1.5.6
Disclosed:
Jan 24, 2023

CVE-2023-23882 on NVD →

Ultimate Addons for Beaver Builder – Lite <= 1.5.4 - Missing Authorization

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 1.5.4. This is due to missing capability on the reload_icons function. This makes it possible for authenticated attackers, with subscriber-level access to delete the '_uabb_enabled_...

CVSS:
5.4
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Jan 23, 2023

Ultimate Addons for Beaver Builder – Lite <= 1.5.4 - Cross-Site Request Forgery

medium

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the reload_icons function. This makes it possible for unauthenticated attackers to invoke this function leading...

CVSS:
5.4
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Jan 23, 2023

CVE-2023-23882 on NVD →

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.5

unknown

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 1.5.4. This is due to missing capability on the reload_icons function. This makes it possible for authenticated attackers, with subscriber-level access to delete the '_uabb_enabled_...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Jan 23, 2023

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.5.5

unknown

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the reload_icons function. This makes it possible for unauthenticated attackers to invoke this function leading...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Jan 23, 2023

Ultimate Addons for Beaver Builder &#8211; Lite [ultimate-addons-for-beaver-builder-lite] < 1.25.0

unknown

From the plugin&#039;s changelog file: &quot;22 Jan 2020 Important Security Update: Update Now! A security researcher privately reported a bug about cross-site scripting (XSS) vulnerability. Our team immediately took action, and provided the required patch within 2 hours, releasing the update on the same day a...

Affected:
up to 1.25.0
Fixed in:
1.25.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database