Authentication Bypass Vulnerability in Ultimate Addons for Beaver Builder by WordPress
CVE-2019-25763
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2026
Badges
What is CVE-2019-25763?
The Ultimate Addons for Beaver Builder version 1.2.4.1 is affected by an authentication bypass vulnerability that allows attackers to gain unauthorized access. This can be achieved through exploiting the social media login form functionality, specifically by sending a crafted POST request to the admin-ajax.php endpoint. By including the appropriate action parameter, a valid administrator email address, and a valid nonce, attackers can obtain session cookies to authenticate as the user, enabling them to perform unauthorized operations.
Affected Version(s)
Ultimate Addons for Beaver Builder 0 < 1.2.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved