CVE-2019-25763 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2019-25763 requires immediate attention.

· 7 min read

Executive Summary

CVE-2019-25763 is a critical authentication bypass affecting WordPress Ultimate Addons for Beaver Builder 1.2.4.1 (CVSS 9.8). An attacker can send a crafted POST request to admin-ajax.php using the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. This can lead to full site takeover, content tampering, malware injection, and credential theft.

Important context: there is no known KEV listing and no confirmed widespread exploitation in the wild, but the impact is severe enough that solo developers and small teams should treat this as an urgent patch-and-verify issue.

Immediate Action

  • Upgrade or remove the vulnerable plugin immediately. If a fixed version is available, update now; otherwise disable the social login feature or deactivate the plugin until you can confirm a safe release. Vendor advisory / changelog
  • Restrict access to WordPress admin endpoints. If possible, limit /wp-admin/ and /wp-admin/admin-ajax.php to trusted IPs or a VPN while you patch.
  • Rotate credentials after patching. Assume any admin session may be exposed. Reset administrator passwords, invalidate sessions, and review API keys and SMTP credentials.
  • Check for compromise. Review recent admin logins, new users, plugin/theme changes, and unexpected posts, redirects, or injected scripts.
  • Take a backup before changes. Snapshot files and database first so you can roll back if the update breaks your site.
  • If you cannot patch today, isolate the site. Put the site behind maintenance mode or a WAF rule blocking requests to the vulnerable AJAX action.

Affected Versions

  • ultimate-addons-for-beaver-builder@1.2.4.1 vulnerable
  • ultimate-addons-for-beaver-builder@<=1.2.4.1 vulnerable unless your vendor advisory states otherwise
  • ultimate-addons-for-beaver-builder@TODO_SAFE_VERSION+ safe; verify against the vendor changelog before deploying

Note: If your environment uses a bundled or managed WordPress image, the vulnerable plugin may be included indirectly. Check both the plugin directory and any container image layers.

Resolution Guide

WordPress / plugin update:

# If you manage WordPress with WP-CLI
wp plugin update ultimate-addons-for-beaver-builder

# If you need to remove it temporarily
wp plugin deactivate ultimate-addons-for-beaver-builder
wp plugin delete ultimate-addons-for-beaver-builder

Composer-managed site (if applicable):

composer show | grep -i beaver
composer update

Linux package / image hygiene:

# Debian/Ubuntu
sudo apt update
sudo apt upgrade

# RHEL/CentOS/Fedora
sudo yum update
# or
sudo dnf upgrade

Docker:

# Rebuild from a patched base image and redeploy
docker pull TODO_PATCHED_IMAGE_TAG
docker compose up -d --build

# If you pin images, move to the fixed tag
# e.g. wordpress:TODO_FIXED_TAG

Hardening: disable the vulnerable feature path

<!-- Example: block the social login form from rendering -->
<?php
if ( function_exists( 'remove_action' ) ) {
    // TODO: replace with the actual hook used by your theme/plugin stack
    remove_action( 'wp_ajax_uabb-lf-google-submit', 'TODO_HANDLER_FUNCTION' );
    remove_action( 'wp_ajax_nopriv_uabb-lf-google-submit', 'TODO_HANDLER_FUNCTION' );
}
?>

Minimal defensive patch idea: ensure the handler rejects unauthenticated or malformed requests and never trusts email alone for login.

<?php
if ( ! is_user_logged_in() ) {
    wp_send_json_error( array( 'message' => 'Authentication required' ), 403 );
}

check_ajax_referer( 'TODO_NONCE_ACTION', 'nonce' );

$user = wp_get_current_user();
if ( ! $user || ! user_can( $user, 'manage_options' ) ) {
    wp_send_json_error( array( 'message' => 'Forbidden' ), 403 );
}
?>

Detection & Verification

Check installed version:

wp plugin list | grep -i 'ultimate-addons-for-beaver-builder'
grep -R "Version:" wp-content/plugins/ultimate-addons-for-beaver-builder/ | head -n 1

Look for the vulnerable action in code:

grep -R "uabb-lf-google-submit" wp-content/plugins/ultimate-addons-for-beaver-builder/
grep -R "admin-ajax.php" wp-content/plugins/ultimate-addons-for-beaver-builder/

Audit for suspicious logins and changes:

# Web server logs
grep -R "uabb-lf-google-submit" /var/log/nginx/ /var/log/apache2/ 2>/dev/null
grep -R "admin-ajax.php" /var/log/nginx/ /var/log/apache2/ 2>/dev/null

# WordPress users
wp user list --fields=ID,user_login,user_email,roles

Verify the fix: after updating, confirm the plugin version is at or above the vendor’s fixed release and that a crafted request no longer returns a session cookie or successful login. Re-test with a non-production copy only.

wp plugin list | grep -i 'ultimate-addons-for-beaver-builder'
# Confirm the version matches TODO_SAFE_VERSION or later

Risk and Impact

This flaw can let an attacker impersonate an administrator without knowing the password, which means full control over the WordPress site. For a solo developer or small team, that can quickly turn into defacement, malicious redirects, spam distribution, data theft, or a foothold into connected services. Because WordPress sites often reuse admin emails and credentials elsewhere, the blast radius can extend beyond the site itself.

Keep reading