CVE-2021-24244 Vulnerability Details
/
/
/
CVE-2021-24244 Metadata Quick Info
CVE Published: 05/05/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021
Source: WPScan |
Vendor: bitorbit |
Product: WPBakery Page Builder (Visual Composer) Clipboard
Status : PUBLISHED
CVE-2021-24244 Description
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-863
CWE Name: CWE-863 Incorrect Authorization
Source: bitorbit
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).