Vulnerabilities and security researches formega-addons-for-visual-composer mega-addons-for-visual-composer
Direction: ascendingJun 07, 2024
Mega Addons For WPBakery Page Builder # CVE-2022-4501
- CVE, Research URL
- Application
- Date
- Dec 15, 2022
- Research Description
- The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.2.7. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Mega Addons For WPBakery Page Builder # CVE-2023-0268
- CVE, Research URL
- Application
- Date
- May 08, 2023
- Research Description
- The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Mega Addons For WPBakery Page Builder # CVE-2022-36798
- CVE, Research URL
- Application
- Date
- Sep 23, 2022
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable