CVE-2021-24243

CVE-2021-24243: WPBakery Page Builder Clipboard < 4.5.6 - Subscriber+ Stored Cross-Site Scripting (XSS)

Vendor Bitorbit
Product WPBakery Page Builder (Visual Composer) Clipboard
Weakness CWE-79 · XSS
Published May 5, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

Key dates

02Disclosure timeline

May 5, 2021 CVE published
August 3, 2024 Record updated