Stored Cross-Site Scripting in WPBakery Page Builder Plugin for WordPress
CVE-2025-11160

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 October 2025

What is CVE-2025-11160?

The WPBakery Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to improper sanitization and escaping of user-input JavaScript code in its Custom JS module. This flaw allows authenticated attackers with contributor-level access or higher to inject malicious web scripts. When users access such modified pages, these scripts are executed, potentially compromising the security of the site and its users. To safeguard your website, it's crucial to ensure you are using the latest version of the plugin and regularly review user access levels.

Affected Version(s)

WPBakery Page Builder * <= 8.6.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.
CVE-2025-11160 : Stored Cross-Site Scripting in WPBakery Page Builder Plugin for WordPress