Access violation vulnerability in Web and WooCommerce Addons for WPBakery Builder 1.4.4.1

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress can be vulnerable to unauthorized access in versions up to and including 1.4.4.1. This means that any authenticated user, like a subscriber, can execute certain AJAX actions and change the plugin settings, as well as inject malicious web scripts. This vulnerability can be avoided by making sure to include capability checks on the AJAX functions.

Detected in:

Web and WooCommerce Addons for WPBakery Builder open vulnerable versions: >= * <= 1.4.4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.