CVE-2021-24244 Vulnerability Details

  /     /     /  

CVE-2021-24244 Metadata Quick Info

CVE Published: 05/05/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: WPScan | Vendor: bitorbit | Product: WPBakery Page Builder (Visual Composer) Clipboard
Status : PUBLISHED

CVE-2021-24244 Description

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-863
CWE Name: CWE-863 Incorrect Authorization
Source: bitorbit

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).