Ultimate Addons Beaver Builder Brainstormforce Ultimate Addons Beaver Builder

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Ultimate Addons Beaver Builder.

By the Year

In 2026 there have been 1 vulnerability in Brainstormforce Ultimate Addons Beaver Builder with an average score of 9.8 out of ten. Ultimate Addons Beaver Builder did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 9.80
2025 0 0.00
2024 9 6.33

It may take a day or so for new Ultimate Addons Beaver Builder vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Ultimate Addons Beaver Builder Security Vulnerabilities

Auth Bypass via Social Media Login in WP Ultimate Addons <1.2.4.1
CVE-2019-25763 9.8 - Critical - June 20, 2026

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user.

Authentication Bypass Using an Alternate Path or Channel

Ultimate Addons for Beaver Builder Lite <=1.5.9 XSS Stored
CVE-2024-43151 5.4 - Medium - August 12, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder Lite: from n/a through 1.5.9.

XSS

Path Traversal in Brainstorm Force UAB <=1.35.13
CVE-2023-51401 6.5 - Medium - May 17, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.

Directory traversal

Privilege Escalation in Brainstorm Force Ultimate Addons 1.35.14
CVE-2023-51398 8.8 - High - May 17, 2024

Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.

Ultimate Addons Beaver Builder Lite XSS via Image Separator widget 1.5.7
CVE-2024-2144 6.4 - Medium - March 30, 2024

The Ultimate Addons for Beaver Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

XSS via Heading widget in Ultimate Addons for Beaver Builder Lite 1.5.7
CVE-2024-2143 6.4 - Medium - March 30, 2024

The Ultimate Addons for Beaver Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Stored XSS in Ultimate Addons for Beaver Builder Lite Info Table widget (1.5.7)
CVE-2024-2142 6.4 - Medium - March 30, 2024

The Ultimate Addons for Beaver Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Ultimate Addons for Beaver Builder Lite: 1.5.7 Stored XSS in Button Widget
CVE-2024-2141 6.4 - Medium - March 30, 2024

The Ultimate Addons for Beaver Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Stored XSS in Ultimate Addons for Beaver Builder Lite (1.5.7) Advanced Icons
CVE-2024-2140 6.4 - Medium - March 30, 2024

The Ultimate Addons for Beaver Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Missing Auth in Brainstorm Force UAB Lite <=1.5.5
CVE-2023-23882 4.3 - Medium - January 17, 2024

Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder Lite.This issue affects Ultimate Addons for Beaver Builder Lite: from n/a through 1.5.5.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Ultimate Addons Beaver Builder or by Brainstormforce? Click the Watch button to subscribe.

subscribe