{"api_version":"1","generated_at":"2026-07-23T13:46:51+00:00","cve":"CVE-2021-24244","urls":{"html":"https://cve.report/CVE-2021-24244","api":"https://cve.report/api/cve/CVE-2021-24244.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24244","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24244"},"summary":{"title":"CVE-2021-24244","description":"An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2021-05-06 13:15:00","updated_at":"2021-05-13 17:35:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://codecanyon.net/item/visual-composer-clipboard/8897711","name":"https://codecanyon.net/item/visual-composer-clipboard/8897711","refsource":"MISC","tags":[],"title":"WPBakery Page Builder Clipboard by bitorbit | CodeCanyon","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wpscan.com/vulnerability/354b98d8-46a1-4189-b347-198701ea59b9","name":"https://wpscan.com/vulnerability/354b98d8-46a1-4189-b347-198701ea59b9","refsource":"CONFIRM","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24244","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24244","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Charles Strader Sweethill","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"24244","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wpbakery_page_builder_clipboard_project","cpe5":"wpbakery_page_builder_clipboard","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-24244","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"WPBakery Page Builder Clipboard < 4.5.8 - Unauthorised Arbitrary License Options Update"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"bitorbit","product":{"product_data":[{"product_name":"WPBakery Page Builder (Visual Composer) Clipboard","version":{"version_data":[{"version_affected":">=","version_name":"4.5.0","version_value":"4.5.0"},{"version_affected":"<","version_name":"4.5.8","version_value":"4.5.8"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email)."}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://codecanyon.net/item/visual-composer-clipboard/8897711","name":"https://codecanyon.net/item/visual-composer-clipboard/8897711"},{"refsource":"CONFIRM","url":"https://wpscan.com/vulnerability/354b98d8-46a1-4189-b347-198701ea59b9","name":"https://wpscan.com/vulnerability/354b98d8-46a1-4189-b347-198701ea59b9"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-863 Incorrect Authorization","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Charles Strader Sweethill"}],"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-05-06 13:15:00","lastModifiedDate":"2021-05-13 17:35:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wpbakery_page_builder_clipboard_project:wpbakery_page_builder_clipboard:*:*:*:*:*:wordpress:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24244","Ordinal":"199006","Title":"CVE-2021-24244","CVE":"CVE-2021-24244","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24244","Ordinal":"1","NoteData":"An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).","Type":"Description","Title":null},{"CveYear":"2021","CveId":"24244","Ordinal":"2","NoteData":"2021-05-05","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"24244","Ordinal":"3","NoteData":"2021-05-05","Type":"Other","Title":"Modified"}]}}}