PT-2024-37733 · WordPress · Web/Woocommerce Addons For Wpbakery Builder

Lucio Sá

·

Published

2024-07-16

·

Updated

2024-07-16

·

CVE-2024-6579

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Web and WooCommerce Addons for WPBakery Builder plugin for WordPress versions prior to 1.4.6
Description The issue allows authenticated attackers with Subscriber-level access and above to modify plugin settings due to a missing capability check on several plugin functions.
Recommendations For versions prior to 1.4.6, update to version 1.4.6 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6579

Affected Products

Web/Woocommerce Addons For Wpbakery Builder