Web and WooCommerce Addons for WPBakery Builder <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 1.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62748 on NVD →
Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] <= 1.5 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Products Web and WooCommerce Addons for WPBakery Builder allows DOM-Based XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through 1.5.
- Affected:
- up to 1.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62748 on NVD →
Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] <= 1.5 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows Stored XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through 1.4.6.
- Affected:
- up to 1.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 29, 2024
CVE-2024-43960 on NVD →
Web and WooCommerce Addons for WPBakery Builder <= 1.4.7 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to in...
- CVSS:
- 4.4
- Affected:
- up to 1.4.7
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2024
CVE-2024-43960 on NVD →
Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] < 1.4.6 (closed)
unknown
[en] The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level ac...
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Jul 16, 2024
CVE-2024-6579 on NVD →
Web and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification
medium
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Jul 15, 2024
CVE-2024-6579 on NVD →
Web and WooCommerce Addons for WPBakery Builder <= 1.4.4.1 - Missing Authorization Checks
medium
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the A...
- CVSS:
- 6.3
- Affected:
- up to 1.4.4.1
- Fixed in:
- 1.4.4.2
- Disclosed:
- Jul 6, 2022
Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] < 1.4.4.1 (closed)
unknown
The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the A...
- Affected:
- up to 1.4.4.1
- Fixed in:
- 1.4.4.1
- Disclosed:
- Jul 6, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database