plugin

Siteorigin Panels Vulnerabilities

20 known security issues reported for the Siteorigin Panels WordPress plugin. Most recent disclosed Jun 26, 2026.

4 high 6 medium

Running Siteorigin Panels on your site? Check whether your installed version is affected.

Scan your site free

Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
6.4
Affected:
up to 2.34.3
Fixed in:
2.34.4
Disclosed:
Jun 26, 2026

CVE-2026-13295 on NVD →

Page Builder by SiteOrigin - Authenticated (Contributor+) Local File Inclusion vulnerability

high

Authenticated (Contributor+) Local File Inclusion vulnerability

CVSS:
8.8
Affected:
up to 2.33.5
Fixed in:
2.34.0
Disclosed:
Mar 2, 2026

Page Builder by SiteOrigin <= 2.33.5 - Authenticated (Contributor+) Local File Inclusion

high

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, al...

CVSS:
8.8
Affected:
up to 2.33.5
Fixed in:
2.34.0
Disclosed:
Mar 2, 2026

CVE-2026-2448 on NVD →

Page Builder by SiteOrigin <= 2.31.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
6.4
Affected:
up to 2.31.4
Fixed in:
2.31.5
Disclosed:
Feb 28, 2025

CVE-2025-1459 on NVD →

Page Builder by SiteOrigin [siteorigin-panels] < 2.31.1

unknown

[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and...

Affected:
up to 2.31.1
Fixed in:
2.31.1
Disclosed:
Jan 14, 2025

CVE-2024-12240 on NVD →

Page Builder by SiteOrigin <= 2.31.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abov...

CVSS:
6.4
Affected:
up to 2.31.0
Fixed in:
2.31.1
Disclosed:
Jan 13, 2025

CVE-2024-12240 on NVD →

Page Builder by SiteOrigin [siteorigin-panels] < 2.29.16

unknown

[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

Affected:
up to 2.29.16
Fixed in:
2.29.16
Disclosed:
May 21, 2024

CVE-2024-4361 on NVD →

Page Builder by SiteOrigin <= 2.29.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'siteorigin_widget' Shortcode

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 2.29.15
Fixed in:
2.29.16
Disclosed:
May 20, 2024

CVE-2024-4361 on NVD →

Page Builder by SiteOrigin [siteorigin-panels] < 2.29.7

unknown

[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

Affected:
up to 2.29.7
Fixed in:
2.29.7
Disclosed:
Mar 23, 2024

CVE-2024-2202 on NVD →

Page Builder by SiteOrigin <= 2.29.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Legacy Image Widget

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...

CVSS:
6.4
Affected:
up to 2.29.6
Fixed in:
2.29.7
Disclosed:
Mar 22, 2024

CVE-2024-2202 on NVD →

Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5

unknown

Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Page Builder by SiteOrigin Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed w...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Jan 12, 2023

Page Builder by SiteOrigin [siteorigin-panels] < 2.10.16

unknown

[en] An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the...

Affected:
up to 2.10.16
Fixed in:
2.10.16
Disclosed:
May 28, 2020

CVE-2020-13643 on NVD →

Page Builder by SiteOrigin [siteorigin-panels] < 2.10.16

unknown

[en] An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the...

Affected:
up to 2.10.16
Fixed in:
2.10.16
Disclosed:
May 28, 2020

CVE-2020-13642 on NVD →

Page Builder by SiteOrigin <= 2.10.15 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

high

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victi...

CVSS:
8.8
Affected:
up to 2.10.16
Fixed in:
2.10.16
Disclosed:
May 11, 2020

CVE-2020-13643 on NVD →

Page Builder by SiteOrigin <= 2.10.15 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

high

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victi...

CVSS:
8.8
Affected:
up to 2.10.15
Fixed in:
2.10.16
Disclosed:
May 5, 2020

CVE-2020-13642 on NVD →

Page Builder by SiteOrigin < 2.0.5 - Reflected Cross-Site Scripting

medium

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘siteorigin_panels_render_form()’ parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
5.3
Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Dec 1, 2015

Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5

unknown

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘siteorigin_panels_render_form()’ parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Dec 1, 2015

Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Jan 12, 2015

Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5

unknown

The Page Builder by SiteOrigin WordPress plugin was affected by a Reflected XSS security vulnerability.

Affected:
up to 2.0.5
Fixed in:
2.0.5

Page Builder by SiteOrigin [siteorigin-panels] < 2.31.5

unknown
Affected:
up to 2.31.5
Fixed in:
2.31.5

CVE-2025-1459 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database