The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.
References
Link | Resource |
---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191a?source=cve | Third Party Advisory |
https://www.wpbeaverbuilder.com/change-logs/ | Product |
https://www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191a?source=cve | Third Party Advisory |
https://www.wpbeaverbuilder.com/change-logs/ | Product |
Configurations
History
06 May 2025, 15:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191a?source=cve - Third Party Advisory | |
References | () https://www.wpbeaverbuilder.com/change-logs/ - Product | |
First Time |
Fastlinemedia
Fastlinemedia beaver Themer |
|
CPE | cpe:2.3:a:fastlinemedia:beaver_themer:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo |
21 Nov 2024, 08:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191a?source=cve - | |
References | () https://www.wpbeaverbuilder.com/change-logs/ - | |
Summary |
|
09 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 19:15
Updated : 2025-05-06 15:53
NVD link : CVE-2023-6695
Mitre link : CVE-2023-6695
CVE.ORG link : CVE-2023-6695
JSON object : View
Products Affected
fastlinemedia
- beaver_themer
CWE