Plugin Vulnerability Hub
Plugin 16 known issues Latest disclosed Oct 17, 2025

WPBakery Page Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin WPBakery Page Builder (`js_composer`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-10006, CVE-2025-11161 and CVE-2025-11160, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
16
High or Critical
2
Patch Coverage
100%
Last Updated
Oct 18, 2025
Priority CVE Quick Links

Fast paths into WPBakery Page Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
15
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WPBakery Page Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
16 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2025-10006, CVE-2025-11161 and CVE-2025-11160
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for WPBakery Page Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-10006
CVE-2025-10006: WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...

Published
Oct 17, 2025
Patched Release
8.7
Affected Versions
Versions up to 8.6
Next Step
Update to 8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11161
CVE-2025-11161: WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied att...

Published
Oct 14, 2025
Patched Release
8.7
Affected Versions
Versions up to 8.6.1
Next Step
Update to 8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11160
CVE-2025-11160: WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to insufficient input sanitization and output escaping of user-supplied JavaScript code in the Custom JS m...

Published
Oct 14, 2025
Patched Release
8.7
Affected Versions
Versions up to 8.6.1
Next Step
Update to 8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7502
CVE-2025-7502: WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...

Published
Aug 05, 2025
Patched Release
8.6
Affected Versions
Versions up to 8.5
Next Step
Update to 8.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4968
CVE-2025-4968: WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator With Text, FAQ, Single Image, Custom Header, Button, Call To Action, Progress Bar, Pie Chart, Roun...

Published
Jul 23, 2025
Patched Release
8.5
Affected Versions
Versions up to 8.4.1
Next Step
Update to 8.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4965
CVE-2025-4965: WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Published
Jun 18, 2025
Patched Release
8.5
Affected Versions
Versions up to 8.4.1
Next Step
Update to 8.5 or newer if supported.
Plugin High Patched: Yes CVE-2024-5709
CVE-2024-5709: WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions gra...

Published
Aug 05, 2024
Patched Release
7.8
Affected Versions
Versions up to 7.7
Next Step
Update to 7.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5708
CVE-2024-5708: WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with A...

Published
Aug 05, 2024
Patched Release
7.8
Affected Versions
Versions up to 7.7
Next Step
Update to 7.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5265
CVE-2024-5265: WPBakery Page Builder <= 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attribu...

Published
Jun 12, 2024
Patched Release
7.7
Affected Versions
Versions up to 7.6
Next Step
Update to 7.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1840
CVE-2024-1840: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu...

Published
Apr 11, 2024
Patched Release
7.6
Affected Versions
Versions up to 7.5
Next Step
Update to 7.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1805
CVE-2024-1805: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

Published
Apr 11, 2024
Patched Release
7.6
Affected Versions
Versions up to 7.5
Next Step
Update to 7.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1842
CVE-2024-1842: WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...

Published
Apr 11, 2024
Patched Release
7.6
Affected Versions
Versions up to 7.5
Next Step
Update to 7.6 or newer if supported.