Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Charles Strader Sweethill

Researcher fromWordfence
#47079of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2021-15786
5.4
2021-05-05
WordPress · Wpbakery Page Builder (Visual Composer) Clipboard · CVE-2021-24243
**Name of the Vulnerable Software and Affected Versions** WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin versions prior to 4.5.6 **Description** The issue concerns an AJAX action in the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin that lacks capability checks and sanitization. This allows users with low privileges (subscriber and above) to call the action and set XSS payloads, which are then triggered on all backend pages. **Recommendations** For WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin versions prior to 4.5.6, update to version 4.5.6 or later to resolve the issue.