CVE-2022-4501: Topdigitaltrends Mega Addons For Wpbakery Page Builder

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings.

Affected products

  • Topdigitaltrends Mega Addons For Wpbakery Page Builder: up to and including 4.2.7

Published 2022-12-14. Last modified 2026-06-17.