vendor:
Ultimate Addons for Beaver Builder
by:
Raphael Karger & Nathan Hrncirik
8.8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Ultimate Addons for Beaver Builder
Affected Version From: Ultimate Addons for Beaver Builder < 1.2.4.1
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 – Authentication Bypass
This exploit allows an attacker to bypass authentication on a Wordpress website using the Ultimate Addons for Beaver Builder plugin version 1.2.4.1 or lower. The attacker needs to know a valid admin/user email address and the page must have a social media login form embedded. The exploit works by sending a POST request to the admin-ajax.php page with the specified email address and a valid nonce.
Mitigation:
Upgrade to the latest version of the Ultimate Addons for Beaver Builder plugin.