CVE-2022-36425: WordPress Beaver Builder plugin <= 2.5.4.3 - Broken Access Control vulnerability
Published Sep 6, 2022
·Updated
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
Affected Software
1 affected component
Fastlinemedia Beaver Builder Wordpress<=2.5.4.3
Remediation
Information
Update to 2.5.4.4 or higher version.
Event History
Sep 6, 2022
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36425?
CVE-2022-36425 has a medium severity rating due to its potential for exploitation in broken access control scenarios.
2
How do I fix CVE-2022-36425?
To fix CVE-2022-36425, update the Beaver Builder plugin to a version greater than 2.5.4.3.
3
What impact does CVE-2022-36425 have on my WordPress site?
CVE-2022-36425 could allow unauthorized users to access restricted areas or data on your WordPress site.
4
Which versions of Beaver Builder are affected by CVE-2022-36425?
CVE-2022-36425 affects all Beaver Builder plugin versions up to and including 2.5.4.3.
5
Is CVE-2022-36425 actively being exploited?
While there are no specific reports of active exploitation, it is recommended to address CVE-2022-36425 promptly to reduce risk.