WordPress security by component
WPBakery Page Builder
Plugin description
WPBakery Page Builder is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Oct 18, 2025; the highest CVE/CNA score is 8.8.
Plugin slug:
page-builderLatest vulnerability
CVE-2025-10006: WPBakery Page Builder: Cross-site scripting
WPBakery Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Oct 18, 2025 |
CVE-2025-10006
WPBakery Page Builder: Cross-site scripting
WPBakery Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Oct 15, 2025 |
CVE-2025-11161
WPBakery Page Builder: Cross-site scripting
WPBakery Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Oct 15, 2025 |
CVE-2025-11160
WPBakery Page Builder: Cross-site scripting
WPBakery Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 06, 2025 |
CVE-2025-7502
WPBakery Page Builder for: Cross-site scripting
WPBakery Page Builder for is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 24, 2025 |
CVE-2025-4968
WPBakery Page Builder for: Cross-site scripting
WPBakery Page Builder for is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 19, 2025 |
CVE-2025-4965
WPBakery Page Builder for: Cross-site scripting
WPBakery Page Builder for is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 01, 2025 |
CVE-2025-1459
Page Builder by SiteOrigin: Cross-site scripting
Page Builder by SiteOrigin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 29, 2024 |
CVE-2024-43953
Classic Addons – WPBakery Page Builder: Cross-site scripting
Classic Addons – WPBakery Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Aug 06, 2024 |
CVE-2024-5709
WPBakery Visual Composer: Filesystem traversal
WPBakery Visual Composer is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVDPending
|
| May 02, 2024 |
CVE-2024-1842
wpbakery: Cross-site scripting
wpbakery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-1841
wpbakery: Cross-site scripting
wpbakery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-1840
wpbakery: Cross-site scripting
wpbakery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-1805
wpbakery: Cross-site scripting
wpbakery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 21, 2023 |
CVE-2022-4669
Page Builder: Live Composer: Cross-site scripting
Page Builder: Live Composer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Nov 16, 2020 |
CVE-2020-28650
Page Builder: Cross-site scripting
Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|