Stored Cross-Site Scripting in Amazing Service Box Addons for WPBakery Page Builder
CVE-2025-2573
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-2573?
The Amazing Service Box Addons for WPBakery Page Builder plugin for WordPress presents a vulnerability that allows for Stored Cross-Site Scripting (XSS) through unchecked SVG file uploads. This issue arises from inadequate input sanitization and output escaping, enabling authenticated users with Author-level access and above to inject malicious scripts into webpages. When other users access these SVG files, the injected scripts are executed, which can lead to various security threats such as data theft or site manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) * <= 2.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved