Cross-site Scripting Vulnerability in WPBakery Visual Composer by Voidcoders
CVE-2025-47659
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-47659?
A Cross-site Scripting (XSS) vulnerability exists in the WPBakery Visual Composer WHMCS Elements provided by Voidcoders, potentially allowing attackers to inject malicious scripts into web pages viewed by users. This vulnerability impacts versions ranging from n/a through 1.0.4.1, enabling the storage and execution of harmful scripts that could compromise user data and overall security. It’s essential for users and site administrators to apply necessary updates and implement security best practices to mitigate potential risks associated with this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPBakery Visual Composer WHMCS Elements <= 1.0.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved