Lucene search

K
wpvulndbWpvulndbWPVDB-ID:16B21256-C76F-49C2-AAC0-DEE96DC163C1
HistoryAug 29, 2022 - 12:00 a.m.

Beaver Builder < 2.5.5.3 - Authenticated Stored XSS via Text Editor

2022-08-2900:00:00
wpscan.com
11
beaver builder
authenticated
stored xss
text editor
cross-site scripting
attacks

EPSS

0.001

Percentile

22.7%

The plugin does not sanitise and escape the Text Editor block, which could allow users with access to the plugin’s editor to perform Cross-Site Scripting attacks

EPSS

0.001

Percentile

22.7%

Related for WPVDB-ID:16B21256-C76F-49C2-AAC0-DEE96DC163C1