Authorization Bypass in Mega Addons Plugin for WordPress
CVE-2022-4501
7.1HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 14 December 2022
What is CVE-2022-4501?
The Mega Addons plugin for WordPress has a vulnerability that allows authenticated users, including those with subscriber-level permissions, to bypass authorization checks. This occurs due to a missing capability verification in the vc_saving_data function, present in versions up to 4.2.7. By exploiting this flaw, attackers can modify critical plugin settings, potentially leading to unauthorized alterations of the site's configuration and functionality.
Affected Version(s)
Mega Addons For WPBakery Page Builder * <= 4.2.7