unitecms Vulnerabilities and Affected Products
Vulnerabilities associated with Unlimited Addons for WPBakery Page Builder.
Products
Clear product- Unlimited Elements For Elementor25 vulnerabilities
- Addon Library1 vulnerability
- addon_library1 vulnerability
- Blox Page Builder1 vulnerability
- blox_page_builder1 vulnerability
- Doubly – Cross Domain Copy Paste for WordPress1 vulnerability
- Unlimited Addons for WPBakery Page Builder1 vulnerability
- Unlimited Elements for Elementor (Premium)1 vulnerability
- unlimited_addons_for_wpbakery_page_builder1 vulnerability
- unlimited_elements_for_elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-6925HIGH | Unlimited Addons for WPBakery Page Builder <= 1.0.42 - Authenticated (Editor+) Arbitrary File UploadThe Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin (the default is editor role, but access can also be granted to contributor role), to upload arbitrary files on the affected site's server which may mak… CWE-434Feb 5, 2024 | CVSS7.2v3.1 | EPSS1.5% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |