CVE-2022-4501: Topdigitaltrends Mega Addons For Wpbakery Page Builder
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings.
Affected products
- Topdigitaltrends Mega Addons For Wpbakery Page Builder: up to and including 4.2.7
Published 2022-12-14. Last modified 2026-06-17.