Access violation vulnerability in Beaver Builder – WordPress Page Builder 1.7

The Beaver Builder WordPress Page Builder plugin, up to and including version 1.7, is vulnerable to an authorization bypass. This means that someone with access to the website, even someone with minimal permissions like a subscriber, can bypass the security checks and call any of the 40+ AJAX actions available. This would allow them to perform many unauthorized actions.

Detected in:

Beaver Builder – WordPress Page Builder fixed vulnerable versions: >= * <= 1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.