Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.34.3
- Fixed in:
- 2.34.4
- Disclosed:
- Jun 26, 2026
CVE-2026-13295 on NVD →
Page Builder by SiteOrigin - Authenticated (Contributor+) Local File Inclusion vulnerability
high
Authenticated (Contributor+) Local File Inclusion vulnerability
- CVSS:
- 8.8
- Affected:
- up to 2.33.5
- Fixed in:
- 2.34.0
- Disclosed:
- Mar 2, 2026
Page Builder by SiteOrigin <= 2.33.5 - Authenticated (Contributor+) Local File Inclusion
high
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, al...
- CVSS:
- 8.8
- Affected:
- up to 2.33.5
- Fixed in:
- 2.34.0
- Disclosed:
- Mar 2, 2026
CVE-2026-2448 on NVD →
Page Builder by SiteOrigin <= 2.31.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 6.4
- Affected:
- up to 2.31.4
- Fixed in:
- 2.31.5
- Disclosed:
- Feb 28, 2025
CVE-2025-1459 on NVD →
Page Builder by SiteOrigin [siteorigin-panels] < 2.31.1
unknown
[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and...
- Affected:
- up to 2.31.1
- Fixed in:
- 2.31.1
- Disclosed:
- Jan 14, 2025
CVE-2024-12240 on NVD →
Page Builder by SiteOrigin <= 2.31.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 2.31.0
- Fixed in:
- 2.31.1
- Disclosed:
- Jan 13, 2025
CVE-2024-12240 on NVD →
Page Builder by SiteOrigin [siteorigin-panels] < 2.29.16
unknown
[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- Affected:
- up to 2.29.16
- Fixed in:
- 2.29.16
- Disclosed:
- May 21, 2024
CVE-2024-4361 on NVD →
Page Builder by SiteOrigin <= 2.29.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'siteorigin_widget' Shortcode
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 2.29.15
- Fixed in:
- 2.29.16
- Disclosed:
- May 20, 2024
CVE-2024-4361 on NVD →
Page Builder by SiteOrigin [siteorigin-panels] < 2.29.7
unknown
[en] The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
- Affected:
- up to 2.29.7
- Fixed in:
- 2.29.7
- Disclosed:
- Mar 23, 2024
CVE-2024-2202 on NVD →
Page Builder by SiteOrigin <= 2.29.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Legacy Image Widget
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 2.29.6
- Fixed in:
- 2.29.7
- Disclosed:
- Mar 22, 2024
CVE-2024-2202 on NVD →
Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5
unknown
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Page Builder by SiteOrigin Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed w...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jan 12, 2023
Page Builder by SiteOrigin [siteorigin-panels] < 2.10.16
unknown
[en] An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the...
- Affected:
- up to 2.10.16
- Fixed in:
- 2.10.16
- Disclosed:
- May 28, 2020
CVE-2020-13643 on NVD →
Page Builder by SiteOrigin [siteorigin-panels] < 2.10.16
unknown
[en] An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the...
- Affected:
- up to 2.10.16
- Fixed in:
- 2.10.16
- Disclosed:
- May 28, 2020
CVE-2020-13642 on NVD →
Page Builder by SiteOrigin <= 2.10.15 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
high
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victi...
- CVSS:
- 8.8
- Affected:
- up to 2.10.16
- Fixed in:
- 2.10.16
- Disclosed:
- May 11, 2020
CVE-2020-13643 on NVD →
Page Builder by SiteOrigin <= 2.10.15 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
high
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victi...
- CVSS:
- 8.8
- Affected:
- up to 2.10.15
- Fixed in:
- 2.10.16
- Disclosed:
- May 5, 2020
CVE-2020-13642 on NVD →
Page Builder by SiteOrigin < 2.0.5 - Reflected Cross-Site Scripting
medium
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘siteorigin_panels_render_form()’ parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...
- CVSS:
- 5.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 1, 2015
Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5
unknown
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘siteorigin_panels_render_form()’ parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 1, 2015
Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jan 12, 2015
Page Builder by SiteOrigin [siteorigin-panels] < 2.0.5
unknown
The Page Builder by SiteOrigin WordPress plugin was affected by a Reflected XSS security vulnerability.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Page Builder by SiteOrigin [siteorigin-panels] < 2.31.5
unknown
- Affected:
- up to 2.31.5
- Fixed in:
- 2.31.5
CVE-2025-1459 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database