CVE-2025-10006
WPBakery
Minimum safe version
8.7
Update to 8.7 or later to address 18 fixable vulnerabilities
CVE-2025-11160
CVE-2025-11161
WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements
WordPress WPBakery Page Builder Plugin <= 8.4.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5709
CVE-2024-5708
CVE-2024-5265
CVE-2024-1842
CVE-2024-1841
CVE-2024-1840
CVE-2024-1805
CVE-2023-31213
WPBakery Page Builder < 4.7.4 - Multiple Unspecified Cross-Site Scripting (XSS)
WPBakery Page Builder for WordPress (formerly Visual Composer) <= 4.7.3 - Multiple Cross-Site Scripting Issues
WordPress Visual Composer Plugin <= 4.7.3 - Cross Site Scripting
CVE-2020-28650