Impact
The WPBakery Page Builder plugin for WordPress contains a stored cross‑site scripting flaw in the rev_slider_vc shortcode in all releases up to 8.6. Unsanitized user attributes allow an authenticated contributor or higher to embed malicious scripts that execute whenever any user views the affected page. This is a classic Client‑Side Injection (CWE‑79) and gives the attacker the ability to run arbitrary JavaScript in the browser context of site visitors.
Affected Systems
The vulnerability affects the WPBakery Page Builder WordPress plugin versions 8.6 and earlier. It requires that the RevSlider plugin is also installed, as the stored scripts are placed into RevSlider‑generated content. Any WordPress site using these plugin versions and with contributors who can edit pages is potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate impact. The EPSS score of less than 1% shows a very low probability of exploitation at the current time, and the vulnerability is not listed in CISA’s KEV catalog. However, the attack vector is limited to users who have Contributor or higher role and have access to page editing while the RevSlider plugin is present. An attacker would need to create or modify a page containing the rev_slider_vc shortcode to inject the script.
OpenCVE Enrichment