Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • The Top 10 Newsletter Strategies to Boost Your Engagement and Reach
    • The Ultimate Cheat Sheet to Holiday Advertising in 2025
    • Data, AI, and the New Era of Creator-Led Growth
    • A Comprehensive Guide to the Future of Influencer Marketing 2025–2026
    • 18 AWeber Alternatives: Our Top Choice Revealed
    • 15+ ConvertKit Alternatives That Deliver Better Results
    • 16 Best GetResponse Alternatives (Tried & Compared)
    • We Tested 15+ SendGrid Alternatives – Discover the #1 for 2025
    YGLuk
    • Home
    • MsLi
      • MsLi’s Digital Products
      • MsLi’s Social Connections
    • Tiktok Specialist
    • TikTok Academy
    • Digital Marketing
    • Influencer Marketing
    • More
      • SEO
      • Digital Marketing Tips
      • Email Marketing
      • Content Marketing
      • SEM
      • Website Traffic
      • Marketing Trends
    YGLuk
    Home » SEO
    SEO

    XSS Vulnerability Affects Beaver Builder WordPress Page Builder

    YGLukBy YGLukApril 2, 2024No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The favored Beaver Builder WordPress Web page Builder was discovered to include an XSS vulnerability that may permit an attacker to inject scripts into the web site that may run when a person visits a webpage.

    Beaver Builder

    Beaver Builder is a well-liked plugin that enables anybody to create knowledgeable trying web site utilizing a straightforward to make use of drag and drop interface. Customers can begin with a predesigned template or create an internet site from scratch.

    Saved Cross Website Scripting (XSS) Vulnerability

    Safety researchers at Wordfence revealed an advisory about an XSS vulnerability affecting the web page builder plugin. An XSS vulnerability is usually present in part of a theme or plugin that enables person enter. The flaw arises when there’s inadequate filtering of what might be enter (a course of referred to as enter sanitization). One other flaw that results in an XSS is inadequate output escaping, which is a safety measure on the output of a plugin that stops dangerous scripts from passing to an internet site browser.

    This particular vulnerability is named a Saved XSS. Saved signifies that an attacker is ready to inject a script immediately onto the webs server. That is totally different from a mirrored XSS which requires a sufferer to click on a hyperlink to the attacked web site with the intention to execute a malicious script. A saved XSS (as impacts the Beaver Builder), is mostly thought of to be extra harmful than a mirrored XSS.

    The safety flaws that gave rise to an XSS vulnerability within the Beaver Builder have been as a result of inadequate enter sanitization and output escaping.

    Wordfence described the vulnerability:

    “The Beaver Builder – WordPress Web page Builder plugin for WordPress is weak to Saved Cross-Website Scripting by way of the plugin’s Button Widget in all variations as much as, and together with, 2.8.0.5 as a result of inadequate enter sanitization and output escaping on person provided attributes. This makes it potential for authenticated attackers, with contributor-level entry and above, to inject arbitrary internet scripts in pages that may execute each time a person accesses an injected web page.”

    The vulnerability is rated 6.4, a medium degree menace. Attackers should achieve at the least contributor-level permission ranges so as to have the ability to launch an assault, which makes this vulnerability a bit more durable to use.

    The official Beaver Builder changelog, which paperwork what’s contained in an replace, notes {that a} patch was issued in model 2.8.0.7.

    The changelog notes:

    “Repair XSS challenge in Button & Button Group Modules when utilizing lightbox”

    Beneficial motion: It’s typically a superb follow to replace and patch a vulnerability earlier than an attacker is ready to exploit it. It’s a best-practice to stage the positioning first earlier than pushing an replace dwell in case that the up to date plugin conflicts with one other plugin or theme.

    Learn the Wordfence advisory:

    Beaver Builder – WordPress Page Builder <= 2.8.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button

    See additionally:

    Featured Picture by Shutterstock/Prostock-studio



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    YGLuk
    • Website

    Related Posts

    Using Google Merchant Center Next For Competitive Analysis

    December 2, 2024

    The Definitive Guide For Your Online Store

    December 2, 2024

    Bluesky Emerges As Traffic Source: Publishers Report 3x Engagement

    December 2, 2024

    Google Chrome site engagement service metrics

    December 2, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    four × 5 =

    Top Posts

    The Top 10 Newsletter Strategies to Boost Your Engagement and Reach

    November 9, 2025

    The Ultimate Cheat Sheet to Holiday Advertising in 2025

    November 7, 2025

    Data, AI, and the New Era of Creator-Led Growth

    November 7, 2025

    A Comprehensive Guide to the Future of Influencer Marketing 2025–2026

    November 7, 2025

    18 AWeber Alternatives: Our Top Choice Revealed

    November 7, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    About us

    Welcome to YGLuk.com – Your Gateway to Digital Success!

    At YGLuk, we are passionate about the ever-evolving world of Digital Marketing and Influencer Marketing. Our mission is to empower businesses and individuals to thrive in the digital landscape by providing valuable insights, expert advice, and the latest trends in the dynamic realm of online marketing.

    We are committed to providing valuable, reliable, and up-to-date information to help you navigate the digital landscape successfully. Whether you are a seasoned professional or just starting, YGLuk is your one-stop destination for all things digital marketing and influencer marketing.

    Top Insights

    The Top 10 Newsletter Strategies to Boost Your Engagement and Reach

    November 9, 2025

    The Ultimate Cheat Sheet to Holiday Advertising in 2025

    November 7, 2025

    Data, AI, and the New Era of Creator-Led Growth

    November 7, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    Copyright © 2024 Ygluk.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.