Beta

Report

Ultimate Addons for Beaver Builder <= 1.35.13 is vulnerable to Limited Arbitrary File Download vulnerability

Contributor
Published
2023-12-25

The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.35.13. This makes it possible for authenticated attackers, with Contributor access and above, to read the contents of a limited subset of arbitrary files on the server, which can contain sensitive information.

CVSS

Score:6.3

Severity:Medium

Version: 1.35.13

There is a patch available in v1.35.14 and we strongly recommend you update to this version as soon as possible.