Stored Cross-Site Scripting in Beaver Builder Addons by WPZOOM Plugin
CVE-2024-2186

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 April 2024

What is CVE-2024-2186?

The Beaver Builder Addons by WPZOOM plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the Team Members widget. This issue allows authenticated attackers with contributor-level privileges to inject arbitrary web scripts, which can be executed on pages accessed by users. It is crucial for website administrators to update to the latest version and apply measures to prevent unauthorized access to maintain site security.

Affected Version(s)

WPZOOM Addons for Beaver Builder 0 <= 1.3.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.