Stored Cross-Site Scripting in Beaver Builder Addons by WPZOOM Plugin
CVE-2024-2186
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-2186?
The Beaver Builder Addons by WPZOOM plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the Team Members widget. This issue allows authenticated attackers with contributor-level privileges to inject arbitrary web scripts, which can be executed on pages accessed by users. It is crucial for website administrators to update to the latest version and apply measures to prevent unauthorized access to maintain site security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Beaver Builder Addons by WPZOOM * <= 1.3.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved