cleantalk

Vulnerabilities and Security Researches

Vulnerabilities and security researches for powerpack-addon-for-beaver-builder

PowerPack Lite for Beaver Builder # CVE-2024-2289

Date
Jun 07, 2024, 04:06:14
Research Description
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Status
vulnerable
Medium
Actual on
Jul 05, 2024, 11:07:02

PowerPack Lite for Beaver Builder # CVE-2022-0176

Date
Jun 07, 2024, 04:06:14
Research Description
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Status
vulnerable
Medium
Actual on
Jul 05, 2024, 11:07:02

PowerPack Lite for Beaver Builder # CVE-2024-37409

Date
Jul 02, 2024, 16:07:35
Research Description
PowerPack Lite for Beaver Builder [powerpack-addon-for-beaver-builder] < 1.3.0.5 CVE-2024-37409
Status
vulnerable
Unknown
Actual on
Jul 05, 2024, 11:07:02

PowerPack Lite for Beaver Builder # CVE-2024-37410

Date
Jul 02, 2024, 16:07:35
Research Description
PowerPack Lite for Beaver Builder [powerpack-addon-for-beaver-builder] < 1.3.0.4 CVE-2024-37410
Status
vulnerable
Unknown
Actual on
Jul 05, 2024, 11:07:02