Stored Cross-Site Scripting Vulnerability in WPBakery Plugin for WordPress
CVE-2024-1842
What is CVE-2024-1842?
The WPBakery Page Builder plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This flaw arises from inadequate input sanitization and output escaping concerning the Custom Heading tag attribute. Authenticated users with contributor privileges or higher can exploit this weakness to inject malicious web scripts into pages. These scripts execute whenever users visit the compromised pages, leading to potential data theft or other malicious actions. It's critical for website administrators to update to the latest version to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPBakery Visual Composer * <= 7.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved