Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ultimatebeaver
Ultimatebeaver ultimate Addons For Beaver Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ultimatebeaver
Ultimatebeaver ultimate Addons For Beaver Builder Wordpress Wordpress wordpress |
Sat, 20 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. | |
| Title | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T13:44:19.812Z
Reserved: 2026-06-20T13:30:11.594Z
Link: CVE-2019-25763
Updated: 2026-06-22T13:44:07.453Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:34:19Z