Stored Cross-Site Scripting in WPBakery Page Builder Plugin for WordPress
CVE-2025-11160
6.4MEDIUM
What is CVE-2025-11160?
The WPBakery Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to improper sanitization and escaping of user-input JavaScript code in its Custom JS module. This flaw allows authenticated attackers with contributor-level access or higher to inject malicious web scripts. When users access such modified pages, these scripts are executed, potentially compromising the security of the site and its users. To safeguard your website, it's crucial to ensure you are using the latest version of the plugin and regularly review user access levels.
Affected Version(s)
WPBakery Page Builder * <= 8.6.1