← WordPress Vulnerabilities
WordPress security by component

PowerPack for Beaver Builder

PowerPack for Beaver Builder is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 18, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: bbpowerpack

CVE-2024-43330: PowerPack for Beaver Builder: Cross-site scripting

PowerPack for Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedAug 18, 2024
Safe version guidanceSee mitigation notes
Safe version
Aug 18, 2024 CVE-2024-43330
PowerPack for Beaver Builder: Cross-site scripting
PowerPack for Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Aug 01, 2024 CVE-2024-39633
PowerPack for Beaver Builder: Privilege escalation or authentication bypass
PowerPack for Beaver Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending