Stored Cross-Site Scripting Vulnerability in Page Builder by SiteOrigin Plugin for WordPress
CVE-2026-13295
What is CVE-2026-13295?
The Page Builder by SiteOrigin plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability through the panels_data parameter. This issue arises from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access and above to inject malicious web scripts. When these scripts are included in pages, they execute whenever a user visits an injected page. Since the nonce and edit_post capability checks are satisfied for Contributor users saving their own posts, the panels_data parameter can be saved as post meta outside the sanitization protections typically enforced by WordPress. As a result, unsanitized content could be rendered on the frontend, making users vulnerable to XSS attacks.
Affected Version(s)
Page Builder by SiteOrigin 0 <= 2.34.3