« Volver al listado

Wpbakery

Wpbakery Page Builder: vulnerabilidades y CVE

Wpbakery Page Builder tiene 20 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE20
Últimos 12 meses5
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-15101Media (6.4)0.20%—1 sept 2026
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output…
CVE-2026-45436Media (6.5)0.30%—17 jun 2026
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
CVE-2025-10006Media (5.4)0.23%—18 oct 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and…
CVE-2025-11161Media (5.4)0.21%—15 oct 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of…
CVE-2025-11160Media (5.4)0.21%—15 oct 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to insufficient input sanitization and output…
CVE-2025-53562Alta (7.1)0.24%—20 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder…
CVE-2025-53559Alta (7.1)0.23%—20 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder…
CVE-2025-48170Alta (7.1)0.23%—20 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder…
CVE-2025-7502Media (5.4)0.22%—6 ago 2025
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and…
CVE-2025-4968Media (5.4)0.27%—24 jul 2025
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator With Text, FAQ, Single Image, Custom…
CVE-2025-4965Media (5.4)0.19%—19 jun 2025
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input…
CVE-2024-43953Media (5.4)0.25%—29 ago 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows Stored…
CVE-2024-5709Alta (8.8)1.0%—6 ago 2024
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with…
CVE-2024-1842Media (5.4)0.32%—2 may 2024
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping.…
CVE-2024-1841Media (5.4)0.32%—2 may 2024
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This…
CVE-2024-1840Media (5.4)0.32%—2 may 2024
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This…
CVE-2024-1805Media (5.4)0.32%—2 may 2024
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This…
CVE-2024-30450Media (6.5)0.36%—29 mar 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Step-Byte-Service GmbH OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) allows Stored…
CVE-2023-31213Media (5.4)0.38%—22 jun 2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPBakery Page Builder plugin <= 6.13.0 versions.
CVE-2020-28650Media (5.4)0.70%—16 nov 2020
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript3
  2. T1189 Drive-by Compromise3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wpbakery