Vulnerabilities > Kutethemes > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-5235 Deserialization of Untrusted Data vulnerability in Kutethemes Ovic Responsive Wpbakery
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'.
network
low complexity
kutethemes CWE-502
8.8