← WordPress Vulnerabilities
WordPress security by component

WPBakery Page Builder

WPBakery Page Builder provides a visual drag-and-drop page builder for creating WordPress layouts.

WPBakery Page Builder (js-composer) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 6.5.

Plugin slug: js-composer

CVE-2026-15101: WPBakery raw-HTML data permits Subscriber-level stored cross-site scripting

WPBakery Page Builder through 8.7.4 accepts attacker-controlled base64 content in the data parameter. Because the encoded value contains no HTML tags, it survives wp_kses_post() during save; the vc_raw_html shortcode template later decodes and emits it without adequate escaping. A Subscriber or higher can store script that executes when another user views the affected page.

PublishedSep 01, 2026
Safe version guidanceSee mitigation notes
Known source slugs: js-composer, js_composer
Published vulnerabilities for js-composer
Safe version
Sep 01, 2026 CVE-2026-15101
WPBakery raw-HTML data permits Subscriber-level stored cross-site scripting
WPBakery Page Builder through 8.7.4 accepts attacker-controlled base64 content in the data parameter. Because the encoded value contains no HTML tags, it survives wp_kses_post() during save; the vc_raw_html shortcode template later decodes and emits it without adequate escaping. A Subscriber or higher can store script that executes when another user views the affected page.
See mitigation notes
CVE6.4
NVDPending
Jun 17, 2026 CVE-2026-45436
WPBakery Page Builder: Broken access control
WPBakery Page Builder is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 8.7.2.
8.7.3
CVE6.5
NVDPending
Jun 22, 2023 CVE-2023-31213
Js_Composer: Cross-site scripting
Js_Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4