Wpbakery

Page Builder

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 06.08.2025 01:45:13
  • Last modified 06.08.2025 20:23:37

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied att...

  • EPSS 0.04%
  • Published 19.06.2025 06:44:49
  • Last modified 10.07.2025 00:01:59

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on ...

  • EPSS 0.22%
  • Published 29.08.2024 18:15:12
  • Last modified 30.08.2024 16:16:01

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Classic Addons Classic Addons – WPBakery Page Builder allows Stored XSS.This issue affects Classic Addons – WPBakery Page Builder: from n/a t...

  • EPSS 0.37%
  • Published 06.08.2024 06:15:34
  • Last modified 28.05.2025 19:48:54

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above,...

  • EPSS 0.21%
  • Published 02.05.2024 17:15:14
  • Last modified 28.05.2025 19:57:05

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authe...

  • EPSS 0.2%
  • Published 02.05.2024 17:15:13
  • Last modified 28.05.2025 19:58:09

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

  • EPSS 0.2%
  • Published 02.05.2024 17:15:13
  • Last modified 28.05.2025 19:57:52

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

  • EPSS 0.2%
  • Published 02.05.2024 17:15:13
  • Last modified 28.05.2025 19:57:36

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

  • EPSS 0.11%
  • Published 22.06.2023 11:15:09
  • Last modified 21.11.2024 08:01:38

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPBakery Page Builder plugin <= 6.13.0 versions.

Exploit
  • EPSS 0.15%
  • Published 16.11.2020 04:15:12
  • Last modified 21.11.2024 05:23:06

The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.