← WordPress Vulnerabilities
WordPress security by component

Export & Import WPBakery Page Builder

Export & Import WPBakery Page Builder (export-import-wpbakery-page-builder) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 7.1.

Plugin slug: export-import-wpbakery-page-builder

CVE-2026-81429: WPBakery template import CSRF stores attacker scripts

Export & Import WPBakery Page Builder through 1.0.2 performs no CSRF check on template import and stores and echoes imported data without sanitization. A forged request can make a logged-in administrator import a crafted template whose JavaScript later executes in the administrator's session. The authoritative export does not name the action, import field, or render context.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for export-import-wpbakery-page-builder
Safe version
Sep 12, 2026 CVE-2026-81429
WPBakery template import CSRF stores attacker scripts
Export & Import WPBakery Page Builder through 1.0.2 performs no CSRF check on template import and stores and echoes imported data without sanitization. A forged request can make a logged-in administrator import a crafted template whose JavaScript later executes in the administrator's session. The authoritative export does not name the action, import field, or render context.
See mitigation notes
CVE7.1
NVDPending