CVE-2024-6579: Web and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change some of the plugin settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Web and WooCommerce Addons for WPBakery Builderto a version that resolves this vulnerability.Fixed in 1.4.5Patch Web and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6579?
CVE-2024-6579 has a high severity level due to the potential for unauthorized modifications to plugin settings.
How do I fix CVE-2024-6579?
To fix CVE-2024-6579, update the Web and WooCommerce Addons for WPBakery Builder plugin to a version higher than 1.4.5.
What systems are affected by CVE-2024-6579?
CVE-2024-6579 affects the Web and WooCommerce Addons for WPBakery Builder plugin for WordPress up to version 1.4.5.
Who discovered CVE-2024-6579?
CVE-2024-6579 was reported by the security community and documented as a vulnerability in the WPBakery plugin.
Is CVE-2024-6579 easy to exploit?
CVE-2024-6579 can be exploited by authenticated users due to a lack of capability checks, making it relatively easy for attackers with valid credentials.