PT-2024-12475 · Beaver Builder+2 · Beaver Builder+3

Rafie Muhammad

·

Published

2024-03-27

·

Updated

2024-03-28

·

CVE-2023-34370

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates versions 3.2.4 and earlier Brainstorm Force Premium Starter Templates versions 3.2.4 and earlier
Description A Server-Side Request Forgery (SSRF) issue affects the software, allowing unauthorized access to internal resources. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates versions 3.2.4 and earlier, update to a version later than 3.2.4. For Brainstorm Force Premium Starter Templates versions 3.2.4 and earlier, update to a version later than 3.2.4. As a temporary workaround, consider restricting access to internal resources to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-34370

Affected Products

Beaver Builder
Brainstorm Force Premium Starter Templates
Brainstorm Force Starter Templates
Elementor