Impact
The Ultimate Addons for WPBakery Page Builder plugin contains a stored cross‑site scripting vulnerability in the Ultimate_VC_Addons::uavc_link_init() function. An attacker with sufficient privileges can embed malicious JavaScript in the ult_buttons shortcode and have it persisted in the content of a WordPress site. When visitors load the affected page, the injected script executes, potentially allowing credential theft, session hijacking, defacement, or other harmful actions. This flaw stems from inadequate input validation and output escaping.
Affected Systems
All WordPress installations that use Ultimate Addons for WPBakery Page Builder version 3.21.4 or older are susceptible. The vulnerability is specific to the button shortcode handling within the shared link‑rendering routine; no other vendors or product versions are currently identified as affected.
Risk and Exploitability
Based on the description, it is inferred that the attacker must be a user who can edit or add content, such as a Contributor or higher role. The stored nature of the flaw means that once injected, the malicious code will affect every visitor who views the compromised page. The CVSS score of 6.1 indicates moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation. The issue is not listed in the CISA KEV catalog, limiting visibility of existing exploitation. However, the potential impact remains high if site roles are not tightly managed or if the plugin is deployed without proper safeguards.
OpenCVE Enrichment