Vulnerabilities and security researches for powerpack-addon-for-beaver-builder
PowerPack Lite for Beaver Builder # CVE-2024-2289
- CVE
- Application
- Date
- Jun 07, 2024, 04:06:14
- Research Description
- The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Status
-
vulnerableMedium
- Actual on
- Jul 05, 2024, 11:07:02
PowerPack Lite for Beaver Builder # CVE-2022-0176
- CVE
- Application
- Date
- Jun 07, 2024, 04:06:14
- Research Description
- The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- Status
-
vulnerableMedium
- Actual on
- Jul 05, 2024, 11:07:02
PowerPack Lite for Beaver Builder # CVE-2024-37409
- CVE
- Application
- Date
- Jul 02, 2024, 16:07:35
- Research Description
- PowerPack Lite for Beaver Builder [powerpack-addon-for-beaver-builder] < 1.3.0.5 CVE-2024-37409
- Status
-
vulnerableUnknown
- Actual on
- Jul 05, 2024, 11:07:02
PowerPack Lite for Beaver Builder # CVE-2024-37410
- CVE
- Application
- Date
- Jul 02, 2024, 16:07:35
- Research Description
- PowerPack Lite for Beaver Builder [powerpack-addon-for-beaver-builder] < 1.3.0.4 CVE-2024-37410
- Status
-
vulnerableUnknown
- Actual on
- Jul 05, 2024, 11:07:02