What the vulnerability does
01Description
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
Explanation of Vulnerability in Simple Terms
Beaver Builder versions up to 2.5.4.3 contain an authorization flaw that allows authenticated users to modify site content and settings they should not have access to. The vulnerability requires a logged-in account but no special privileges. An attacker with basic user access can alter page layouts, content, and potentially site configuration, affecting site integrity.
What an attacker can do
Modify page content and site settings without proper authorization.
Potential impact on your site
Unauthorized users can alter published pages, layouts, and settings, requiring content restoration and access review.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities