What the vulnerability does
01Description
Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.
Explanation of Vulnerability in Simple Terms
Live Composer Page Builder versions up to 1.5.38 lack proper authorization checks on certain administrative functions. An authenticated user with high-level privileges can access or modify restricted settings without proper permission validation. This allows privilege escalation within the plugin's administrative interface, potentially exposing or altering site configuration.
What an attacker can do
Read or modify restricted plugin settings if they have high-level admin access.
Potential impact on your site
Admins with elevated privileges could bypass intended permission controls and access sensitive plugin settings.
Conditions required to exploit
Attacker must have high-level administrative privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities