Back to overview

CVE-2019-25763

CRITICAL
9.8
CVSS 3.1
Description
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user.

Metadata

CVE ID
CVE-2019-25763
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-20 13:30 UTC
Published
2026-06-20 13:36 UTC
Last updated
2026-06-20 13:36 UTC
Primary CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
Vendor / Product
Ultimatebeaver / Ultimate Addons for Beaver Builder
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Ultimatebeaver Ultimate Addons for Beaver Builder 0 < 1.2.4.1
Weakness (CWE)
CWESourceDescription
CWE-288 cna Authentication Bypass Using an Alternate Path or Channel
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (3)
Back to overview