The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'gambit_builder_save_content' function in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and above, to insert arbitrary content into existing posts.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 08 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Pagebuildersandwich Pagebuildersandwich page Builder Sandwich | |
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:pagebuildersandwich:page_builder_sandwich:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Pagebuildersandwich Pagebuildersandwich page Builder Sandwich | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-05T01:56:00.972Z
Updated: 2024-08-01T18:33:25.421Z
Reserved: 2024-02-06T18:41:58.980Z
Link: CVE-2024-1285
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T18:33:25.421Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-03-05T02:15:26.447
Modified: 2025-01-08T17:13:54.647
Link: CVE-2024-1285
 Redhat
                        Redhat
                    No data.