CVE-2024-30425: WordPress Beaver Builder plugin <= 2.7.4.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows DOM-Based XSS.This issue affects Beaver Builder: from n/a through <= 2.7.4.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30425?
CVE-2024-30425 is classified as a critical severity vulnerability due to the potential for remote code execution through stored Cross-Site Scripting (XSS).
How do I fix CVE-2024-30425?
To fix CVE-2024-30425, update Beaver Builder to the latest version above 2.7.4.4, ensuring that all plugins and themes are also up to date.
What types of attacks can be executed through CVE-2024-30425?
CVE-2024-30425 allows attackers to perform stored XSS attacks, potentially leading to data theft or session hijacking.
Which versions of Beaver Builder are affected by CVE-2024-30425?
CVE-2024-30425 affects all versions of Beaver Builder from n/a to 2.7.4.4.
Is there a patch available for CVE-2024-30425?
Yes, a patch is included in the latest release of Beaver Builder, which addresses the vulnerability.