CVE-2019-25763: WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25763?
CVE-2019-25763 has a critical severity score of 9.8.
How does CVE-2019-25763 affect users?
CVE-2019-25763 allows attackers to bypass authentication and gain unauthorized access to WordPress sites using the Ultimate Addons for Beaver Builder.
What impact does CVE-2019-25763 have on a WordPress site?
CVE-2019-25763 can lead to full administrative access, compromising sensitive data and site integrity for affected WordPress installations.
How do I fix CVE-2019-25763?
To fix CVE-2019-25763, update the Ultimate Addons for Beaver Builder plugin to the latest version provided by Brainstorm Force.
When was CVE-2019-25763 published?
CVE-2019-25763 was published on June 20, 2026.