CVE-2021-24243 Information
Jun 07, 2022
cve
Description
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization allowing low privilege users (subscriber+) to call it and set XSS payloads which will be triggered in all backend pages.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://wpscan.com/vulnerability/3bc0733a-b949-40c9-a5fb-f56814fc4af3 https://codecanyon.net/item/visual-composer-clipboard/8897711
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: