Cross-site Scripting Vulnerability in WPBakery Visual Composer by Voidcoders
CVE-2025-47659
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-47659?
A Cross-site Scripting (XSS) vulnerability exists in the WPBakery Visual Composer WHMCS Elements provided by Voidcoders, potentially allowing attackers to inject malicious scripts into web pages viewed by users. This vulnerability impacts versions ranging from n/a through 1.0.4.1, enabling the storage and execution of harmful scripts that could compromise user data and overall security. It’s essential for users and site administrators to apply necessary updates and implement security best practices to mitigate potential risks associated with this flaw.
Affected Version(s)
WPBakery Visual Composer WHMCS Elements <= 1.0.4.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
zaim (Patchstack Alliance)