Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Topdigitaltrends Subscribe
Filtered by product Mega Addons For Wpbakery Page Builder
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4501 1 Topdigitaltrends 1 Mega Addons For Wpbakery Page Builder 2022-12-20 N/A 6.5 MEDIUM
The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.2.7. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings.
CVE-2022-36798 1 Topdigitaltrends 1 Mega Addons For Wpbakery Page Builder 2022-09-23 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.