WPBakery Page Builder Clipboard
cpe:2.3:a:wpbakery_page_builder_clipboard_project:wpbakery_page_builder_clipboard:*:*:*:*:wordpress:*:*
- < 4.5.8
A vulnerability exists in the WPBakery Page Builder Clipboard WordPress plugin in versions prior to 4.5.8. An AJAX action registered by the plugin lacked proper capability checks, enabling low-privilege users, such as subscribers, to unauthorizedly update license options, including the license key and email.
Exploitation of this vulnerability allows low-privilege users to arbitrarily update license information, potentially leading to unauthorized access or privileges.
To reproduce this vulnerability, log in as a user with a subscriber role or higher. Send a request to 'wp-admin/admin-ajax.php' with the action 'vc_clipboard_activate'. Include arbitrary data in the 'email' and 'license_key' parameters. The absence of capability checks will allow the request to be processed, updating the license options with the provided data.
Users are advised to update the WPBakery Page Builder Clipboard WordPress plugin to version 4.5.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.