Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

WPBakery Page Builder — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in WPBakery Page Builder, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the WPBakery Page Builder product, categorized under software weaknesses and tagged for vendor-specific tracking. It collects reported security flaws, including remote code execution, cross-site scripting, and authorization bypass issues, covering incidents from early 2016 through the present. Here, you can track the vendor’s advisory history, understand the prevalence of specific weakness classes within this popular WordPress plugin, and review the product’s long-term vulnerability timeline to assess risk exposure. The data reflects publicly disclosed security issues and patch releases, providing a chronological view of how vulnerabilities were introduced, exploited, and mitigated over time. By examining these records, security professionals can identify patterns in code quality, evaluate the effectiveness of updates, and compare the stability of WPBakery against other page builders. This resource serves as a historical archive of security incidents, helping users and administrators make informed decisions about plugin usage and configuration. It does not include unreported or zero-day vulnerabilities, focusing solely on verified and published advisories. The scope is limited to technical weaknesses that impact confidentiality, integrity, or availability, excluding general bugs or non-security related defects. Users can filter by year or severity to pinpoint critical periods of instability or rapid patching. This aggregation aims to provide transparency into the product’s security posture without speculating on unverified claims.

Vendor: WPBakery

CVE IDTitleCVSSSeverityPublished
CVE-2025-10006 WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-10-18
CVE-2025-11160 WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module CWE-80 6.4 Medium2025-10-15
CVE-2025-11161 WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode CWE-80 6.4 Medium2025-10-15
CVE-2025-7502 WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-08-06
CVE-2025-4968 WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements CWE-79 6.4 Medium2025-07-24
CVE-2025-4965 WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder CWE-79 6.4 Medium2025-06-19
CVE-2024-5708 WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-08-06
CVE-2024-5709 WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion CWE-22 8.8 High2024-08-06
CVE-2024-5265 WPBakery Page Builder <= 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute CWE-79 6.4 Medium2024-06-13
CVE-2024-1840 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author CWE-79 6.4 Medium2024-05-02
CVE-2024-1805 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute CWE-79 6.4 Medium2024-05-02
CVE-2024-1842 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute CWE-79 6.4 Medium2024-05-02
CVE-2024-1841 WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title tag attribute CWE-79 6.4 Medium2024-05-02
CVE-2023-31213 WordPress WPBakery Page Builder Plugin < 6.13.0 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-06-22

All 14 known CVE vulnerabilities affecting WPBakery Page Builder with full Chinese analysis, references, and POCs where available.