CVE-2021-24243
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be…
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wpbakery page builder clipboard project/wpbakery page builder clipboard
- Source
- contact@wpscan.com
References
- https://codecanyon.net/item/visual-composer-clipboard/8897711Product, Third Party Advisory
- https://wpscan.com/vulnerability/3bc0733a-b949-40c9-a5fb-f56814fc4af3Exploit, Third Party Advisory
- https://codecanyon.net/item/visual-composer-clipboard/8897711Product, Third Party Advisory
- https://wpscan.com/vulnerability/3bc0733a-b949-40c9-a5fb-f56814fc4af3Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.