Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.8.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a DOM-based Cross‑Site Scripting flaw in the Techeshta Card Elements for WPBakery plugin, allowing an attacker to inject malicious scripts during web page generation. This code injection occurs because the plugin fails to properly neutralize user input before rendering it to the browser, potentially enabling arbitrary client‑side script execution in the context of a victim’s browser. The weakness is classified as CWE‑79, which denotes improper neutralization of input.

Affected Systems

This issue impacts the Card Elements for WPBakery plugin for WordPress, versions up through and including 1.0.8. The plugin is distributed by Techeshta and is widely used in WordPress installations that incorporate WPBakery page builder functionality.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score reflects a very low likelihood of exploitation (less than 1%). The vulnerability is not listed in the CISA KEV catalog. Because the flaw is DOM‑based, it can be triggered by user‑controlled input rendered on the page, making it potentially exploitable by anyone who can create or manipulate a card element. The impact is restricted to client‑side script execution, but if combined with phishing or social engineering, it can lead to credential theft or session hijacking. Attackers would typically craft malicious input and submit it via the front‑end, exploiting the lack of output encoding. Given the low EPSS score, the risk is moderate, but the widespread use of the plugin warrants prompt remediation.

Generated by OpenCVE AI on April 30, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Card Elements for WPBakery plugin to the latest available version; if no newer release exists, request a security fix from the vendor.
  • Ensure that all user‑provided data destined for card elements is properly sanitised and escaped before rendering, following WordPress best practices for output encoding.
  • Implement a content security policy (CSP) and/or use a reputable web application firewall to block execution of injected scripts during page load.

Generated by OpenCVE AI on April 30, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30619 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery allows DOM-Based XSS. This issue affects Card Elements for WPBakery: from n/a through 1.0.8.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.8.
Title WordPress Card Elements for WPBakery plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability WordPress Card Elements for WPBakery Plugin <= 1.0.8 - Cross Site Scripting (XSS) Vulnerability

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.9.
Title WordPress Card Elements for WPBakery Plugin <= 1.0.8 - Cross Site Scripting (XSS) Vulnerability WordPress Card Elements for WPBakery plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery allows DOM-Based XSS. This issue affects Card Elements for WPBakery: from n/a through 1.0.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery card-elements-for-wpbakery allows DOM-Based XSS.This issue affects Card Elements for WPBakery: from n/a through <= 1.0.8.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Techeshta
Techeshta card Elements For Wpbakery
Wordpress
Wordpress wordpress
Vendors & Products Techeshta
Techeshta card Elements For Wpbakery
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techeshta Card Elements for WPBakery allows DOM-Based XSS. This issue affects Card Elements for WPBakery: from n/a through 1.0.8.
Title WordPress Card Elements for WPBakery Plugin <= 1.0.8 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Techeshta Card Elements For Wpbakery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:29:49.619Z

Reserved: 2025-08-27T16:19:19.005Z

Link: CVE-2025-58220

cve-icon Vulnrichment

Updated: 2025-09-23T15:55:47.863Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:06.663

Modified: 2026-04-28T19:34:05.393

Link: CVE-2025-58220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:30:24Z

Weaknesses