WPBakery Page Builder Clipboard [vc_clipboard] < 4.5.6
unknown
[en] An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- May 5, 2021
CVE-2021-24243 on NVD →
WPBakery Page Builder Clipboard [vc_clipboard] < 4.5.8
unknown
[en] An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
- Affected:
- up to 4.5.8
- Fixed in:
- 4.5.8
- Disclosed:
- May 5, 2021
CVE-2021-24244 on NVD →
WPBakery Page Builder Clipboard < 4.5.8 - Arbitrary License Options Update
medium
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
- CVSS:
- 6.5
- Affected:
- up to 4.5.8
- Fixed in:
- 4.5.8
- Disclosed:
- Apr 6, 2021
CVE-2021-24244 on NVD →
WPBakery Page Builder Clipboard <= 4.5.5 - Stored Cross-Site Scripting
medium
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
- CVSS:
- 6.4
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Apr 3, 2021
CVE-2021-24243 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database