Stored Cross-Site Scripting Vulnerability in WPBakery Plugin for WordPress
CVE-2024-1842
5.4MEDIUM
What is CVE-2024-1842?
The WPBakery Page Builder plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This flaw arises from inadequate input sanitization and output escaping concerning the Custom Heading tag attribute. Authenticated users with contributor privileges or higher can exploit this weakness to inject malicious web scripts into pages. These scripts execute whenever users visit the compromised pages, leading to potential data theft or other malicious actions. It's critical for website administrators to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
WPBakery Visual Composer * <= 7.5