WordPress Plugin Vulnerabilities

Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF

Description

The plugin does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Suhayb Ahmed (cyboltx)
Submitter
Suhayb Ahmed (cyboltx)
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other