unitecms Vulnerabilities and Affected Products
Vulnerabilities associated with blox_page_builder.
Products
Clear product- Unlimited Elements For Elementor25 vulnerabilities
- Addon Library1 vulnerability
- addon_library1 vulnerability
- Blox Page Builder1 vulnerability
- blox_page_builder1 vulnerability
- Doubly – Cross Domain Copy Paste for WordPress1 vulnerability
- Unlimited Addons for WPBakery Page Builder1 vulnerability
- Unlimited Elements for Elementor (Premium)1 vulnerability
- unlimited_addons_for_wpbakery_page_builder1 vulnerability
- unlimited_elements_for_elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-6315HIGH | Blox Page Builder <= 1.0.65 - Authenticated (Contributor+) Arbitrary File UploadThe Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all versions up to, and including, 1.0.65. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible. CWE-434Aug 6, 2024 | CVSS8.8v3.1 | EPSS0.969% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |