
Cloud Vulnerability DB
A community-led vulnerabilities database
The CVE-2024-32957 is a Missing Authorization vulnerability affecting the WordPress Page Builder: Live Composer plugin through version 1.5.38. The vulnerability was discovered by researcher Phill Sav (Savphill) and was publicly disclosed on April 23, 2024 (WPScan, Patchstack).
The vulnerability stems from a missing capability check in the dslc_ajax_add_module() function, which allows authenticated users with author-level access and above to add modules without proper authorization. The vulnerability has been assigned a CVSS v3.1 score of 4.7 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L. It is classified as CWE-862: Missing Authorization (WPScan).
The vulnerability enables authenticated attackers with author-level access or higher to perform unauthorized modification of data through module addition in the Page Builder: Live Composer plugin (Patchstack).
The vulnerability requires an authenticated user with author-level privileges to exploit. It has been classified as a broken access control issue, which falls under the OWASP Top 10 category A5: Broken Access Control (WPScan).
The vulnerability has been fixed in version 1.5.39 of the Page Builder: Live Composer plugin. Users are advised to update to this version or later to remediate the security issue. Additionally, Patchstack has issued a virtual patch to mitigate this issue by blocking potential attacks until users can update to the fixed version (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."