Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual Composer) Page Builder: from n/a through <= 1.3.2.
Published: 2026-02-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw due to improper neutralization of user input when generating web pages. An attacker can inject malicious scripts into URLs or form fields that the plugin processes without adequate output encoding. The resulting script execution can steal user session cookies, deface content, or redirect users to malicious sites, affecting confidentiality and integrity of the web application.

Affected Systems

Affected systems include sites running the Business Template Blocks for WPBakery (Visual Composer) Page Builder plugin from any earlier release through version 1.3.2, as supplied by the vendor themebon. The flaw exists in the plugin templates and addons data handling logic that predates the 1.3.3 update.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% shows the exploitation probability is currently very low. It is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTTP request that includes malicious script payloads in query parameters or POST data processed by the plugin; an authenticated or public user is not required if the site exposes the vulnerable endpoint to unauthenticated traffic.

Generated by OpenCVE AI on April 27, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Business Template Blocks for WPBakery plugin to the latest secure version (≥ 1.3.3) from themebon’s official source.
  • If an update is not available, uninstall the plugin to remove the vulnerable code.
  • Restrict access to the plugin’s administrative interfaces to administrators only, and avoid exposing any endpoints that process unsanitized input to public users.

Generated by OpenCVE AI on April 27, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themebon
Themebon business Template Blocks For Wpbakery (visual Composer) Page Builder
Wordpress
Wordpress wordpress
Vendors & Products Themebon
Themebon business Template Blocks For Wpbakery (visual Composer) Page Builder
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual Composer) Page Builder: from n/a through <= 1.3.2.
Title WordPress Business Template Blocks for WPBakery (Visual Composer) Page Builder plugin <= 1.3.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Themebon Business Template Blocks For Wpbakery (visual Composer) Page Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:58:45.857Z

Reserved: 2025-12-31T20:13:11.108Z

Link: CVE-2025-69390

cve-icon Vulnrichment

Updated: 2026-02-23T21:27:43.404Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:24.433

Modified: 2026-06-17T10:00:36.500

Link: CVE-2025-69390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T20:30:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')