Wpbakery
Wpbakery Page Builder: vulnerabilidades y CVE
Wpbakery Page Builder tiene 20 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15101 | Media (6.4) | 0.20% | — | 1 sept 2026 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output… |
| CVE-2026-45436 | Media (6.5) | 0.30% | — | 17 jun 2026 | Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. |
| CVE-2025-10006 | Media (5.4) | 0.23% | — | 18 oct 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and… |
| CVE-2025-11161 | Media (5.4) | 0.21% | — | 15 oct 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of… |
| CVE-2025-11160 | Media (5.4) | 0.21% | — | 15 oct 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to insufficient input sanitization and output… |
| CVE-2025-53562 | Alta (7.1) | 0.24% | — | 20 ago 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder… |
| CVE-2025-53559 | Alta (7.1) | 0.23% | — | 20 ago 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder… |
| CVE-2025-48170 | Alta (7.1) | 0.23% | — | 20 ago 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder… |
| CVE-2025-7502 | Media (5.4) | 0.22% | — | 6 ago 2025 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and… |
| CVE-2025-4968 | Media (5.4) | 0.27% | — | 24 jul 2025 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator With Text, FAQ, Single Image, Custom… |
| CVE-2025-4965 | Media (5.4) | 0.19% | — | 19 jun 2025 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input… |
| CVE-2024-43953 | Media (5.4) | 0.25% | — | 29 ago 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows Stored… |
| CVE-2024-5709 | Alta (8.8) | 1.0% | — | 6 ago 2024 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with… |
| CVE-2024-1842 | Media (5.4) | 0.32% | — | 2 may 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping.… |
| CVE-2024-1841 | Media (5.4) | 0.32% | — | 2 may 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-1840 | Media (5.4) | 0.32% | — | 2 may 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-1805 | Media (5.4) | 0.32% | — | 2 may 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-30450 | Media (6.5) | 0.36% | — | 29 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Step-Byte-Service GmbH OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) allows Stored… |
| CVE-2023-31213 | Media (5.4) | 0.38% | — | 22 jun 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPBakery Page Builder plugin <= 6.13.0 versions. |
| CVE-2020-28650 | Media (5.4) | 0.70% | — | 16 nov 2020 | The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.