PT-2023-16853 · Wpbakery · Pricing Tables For Wpbakery Page Builder

·

CVE-2023-1274

·

Publicado

2023-04-17

·

Atualizado

2023-04-25

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pricing Tables For WPBakery Page Builder (formerly Visual Composer) versions prior to 3.0
Description The issue allows any authenticated users, such as subscribers, to perform Local File Inclusion (LFI) attacks due to the lack of validation of some shortcode attributes. These attributes are used to generate paths that are passed to include functions.
Recommendations For versions prior to 3.0, update to version 3.0 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-1274

Produtos afetados

Pricing Tables For Wpbakery Page Builder