Description
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23541 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-03T19:24:13.637Z
Reserved: 2023-03-08T15:34:52.098Z
Link: CVE-2023-1274
Updated: 2024-08-02T05:40:59.700Z
Status : Modified
Published: 2023-04-17T13:15:38.060
Modified: 2024-11-21T07:38:48.380
Link: CVE-2023-1274
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD