Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the Grid Builder feature of WPBakery Page Builder. The plugin fails to sanitize and escape user‑supplied attributes, allowing an authenticated user with author or higher privileges to embed malicious JavaScript into a page. Whenever any visitor loads the compromised page, the injected script executes in their browser, enabling attackers to steal session cookies, deface content, or perform other actions within the context of the logged‑in user.
Affected Systems
Affected are all instances of the WPBakery Page Builder plugin for WordPress version 8.4.1 and earlier. The issue applies to the Grid Builder component in those releases, regardless of the WordPress core version.
Risk and Exploitability
The CVSS base score is 6.4, indicating a moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Attackers must be authenticated at author level or higher, but the resulting cross‑site scripting can affect any user who views the injected page, providing an indirect but potentially wide impact. The correct mitigations are applying a patch or disabling the vulnerable feature.
OpenCVE Enrichment
EUVD