WPBakery Page Builder

WPBakery Page Builder has 18 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 18 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 14 of the records (78%). Other recurring categories include Improper Neutralization Of Script-Related HTML Tags In A Web Page (Basic XSS), Missing Authorization.

Every one of the 18 issues recorded for WPBakery Page Builder has a vendor fix available, so running the current release closes all known holes.

10 independent researchers contributed these findings, most of them (4) reported by Nikolas.

01234567891010.02.2015Today10.02.20157.2WPBakery Page Builder for WordPress (formerly Visual Composer) <= 4.7.3 - Multiple Cross-Site Scripting Issues CVSS 7.2 · 10.02.201507.10.20206.4WPBakery Page Builder for WordPress <= 6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 07.10.202020.06.20236.4WPBakery Page Builder for WordPress <= 6.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.06.202311.04.20246.4WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title tag attribute CVSS 6.4 · 11.04.20246.4WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute CVSS 6.4 · 11.04.20246.4WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute CVSS 6.4 · 11.04.20246.4WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author CVSS 6.4 · 11.04.202412.06.20246.4WPBakery Page Builder <= 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute CVSS 6.4 · 12.06.202405.08.20246.4WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 05.08.20248.8WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion CVSS 8.8 · 05.08.202418.06.20256.4WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder CVSS 6.4 · 18.06.202523.07.20256.4WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements CVSS 6.4 · 23.07.202505.08.20256.4WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 05.08.202514.10.20256.4WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via Custom JS Module CVSS 6.4 · 14.10.20256.4WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode CVSS 6.4 · 14.10.202517.10.20256.4WPBakery Page Builder <= 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.10.202513.05.20264.3WPBakery Page Builder <= 8.7.2 - Missing Authorization CVSS 4.3 · 13.05.202631.08.20266.4WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter CVSS 6.4 · 31.08.2026

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

18

Get automatic notifications for all WPBakery Page Builder vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-5709

WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion

Read the full analysis

Vulnerability Records

18 records
2026-08-31 21:00CVE-2026-15101
6.4
Medium
d.v4n_s3cYes
2026-05-13 00:00CVE-2026-45436
4.3
Medium
Ethan ConsultingYes
2025-10-17 18:22CVE-2025-10006
6.4
Medium
stealthcopterYes
2025-10-14 17:32CVE-2025-11161
6.4
Medium
Muhammad Yudha - DJYes
2025-10-14 17:29CVE-2025-11160
6.4
Medium
Muhammad Yudha - DJYes
2025-08-05 00:00CVE-2025-7502
6.4
Medium
stealthcopterYes
2025-07-23 00:00CVE-2025-4968
6.4
Medium
zer0gh0stYes
2025-06-18 00:00CVE-2025-4965
6.4
Medium
zer0gh0stYes
2024-08-05 00:00CVE-2024-5708
6.4
Medium
João Pedro Soares de AlcântaraYes
2024-08-05 00:00CVE-2024-5709
8.8
High
João Pedro Soares de AlcântaraYes
Showing 1–10 of 18 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C