Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

WPBakery Page Builder — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in WPBakery Page Builder, with AI-generated Chinese analysis, references, and POCs.

Vendor: WPBakery

CVE IDTitleCVSSSeverityPublished
CVE-2025-10006 WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-10-18
CVE-2025-11160 WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module CWE-80 6.4 Medium2025-10-15
CVE-2025-11161 WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode CWE-80 6.4 Medium2025-10-15
CVE-2025-7502 WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-08-06
CVE-2025-4968 WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements CWE-79 6.4 Medium2025-07-24
CVE-2025-4965 WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder CWE-79 6.4 Medium2025-06-19
CVE-2024-5708 WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-08-06
CVE-2024-5709 WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion CWE-22 8.8 High2024-08-06
CVE-2024-5265 WPBakery Page Builder <= 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute CWE-79 6.4 Medium2024-06-13
CVE-2024-1840 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author CWE-79 6.4 Medium2024-05-02
CVE-2024-1805 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute CWE-79 6.4 Medium2024-05-02
CVE-2024-1842 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute CWE-79 6.4 Medium2024-05-02
CVE-2024-1841 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title tag attribute CWE-79 6.4 Medium2024-05-02
CVE-2023-31213 WordPress WPBakery Page Builder Plugin < 6.13.0 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-06-22

All 14 known CVE vulnerabilities affecting WPBakery Page Builder with full Chinese analysis, references, and POCs where available.