CVE Database
/

CVE-2021-24244

Back to search

CVE-2021-24244

Published: May 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

VendorProductVersions

bitorbit

WPBakery Page Builder (Visual Composer) Clipboard

affected
4.5.0 - < 4.5.0*
affected
4.5.8 - < 4.5.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now