CVE-2024-13592 is a Local File Inclusion vulnerability affecting all versions of the Team Builder For WPBakery Page Builder WordPress plugin up to and including 1.0. This flaw allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server via the 'team-builder-vc' shortcode. Rated 8.8 HIGH on the CVSS scale, successful exploitation can lead to arbitrary PHP code execution, bypassing access controls, sensitive data exfiltration, or full system compromise. There is currently no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:webdevocean:team-builder-for-wpbakery-page-builder:1.0:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.