What the vulnerability does
01Description
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.
Explanation of Vulnerability in Simple Terms
Ultimate Addons for Beaver Builder versions up to 1.35.14 contain a privilege management flaw that allows authenticated users with low-level permissions to perform actions restricted to higher-privilege roles. An attacker with a basic user account can read, modify, or delete sensitive site data and functionality. Update to a version newer than 1.35.14 to resolve this issue.
What an attacker can do
Read, modify, or delete site data and functionality beyond their assigned permission level.
Potential impact on your site
Unauthorized users can access and alter protected content, settings, or site functionality reserved for administrators.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities