Stored Cross-Site Scripting in Beaver Builder Addons by WPZOOM Plugin
CVE-2024-2186
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-2186?
The Beaver Builder Addons by WPZOOM plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the Team Members widget. This issue allows authenticated attackers with contributor-level privileges to inject arbitrary web scripts, which can be executed on pages accessed by users. It is crucial for website administrators to update to the latest version and apply measures to prevent unauthorized access to maintain site security.
Affected Version(s)
Beaver Builder Addons by WPZOOM * <= 1.3.4