plugin

Vc Addons By Bit14 Vulnerabilities

8 known security issues reported for the Vc Addons By Bit14 WordPress plugin. Most recent disclosed Dec 31, 2025.

4 medium

Running Vc Addons By Bit14 on your site? Check whether your installed version is affected.

Scan your site free

Web and WooCommerce Addons for WPBakery Builder <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...

CVSS:
6.4
Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-62748 on NVD →

Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] <= 1.5 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Products Web and WooCommerce Addons for WPBakery Builder allows DOM-Based XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through 1.5.

Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-62748 on NVD →

Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] <= 1.5 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows Stored XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through 1.4.6.

Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Aug 29, 2024

CVE-2024-43960 on NVD →

Web and WooCommerce Addons for WPBakery Builder <= 1.4.7 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to in...

CVSS:
4.4
Affected:
up to 1.4.7
Fix:
No patched version reported
Disclosed:
Aug 26, 2024

CVE-2024-43960 on NVD →

Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] < 1.4.6 (closed)

unknown

[en] The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level ac...

Affected:
up to 1.4.6
Fixed in:
1.4.6
Disclosed:
Jul 16, 2024

CVE-2024-6579 on NVD →

Web and WooCommerce Addons for WPBakery Builder <= 1.4.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification

medium

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings modification due to a missing capability check on several plugin functions in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
4.3
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
Jul 15, 2024

CVE-2024-6579 on NVD →

Web and WooCommerce Addons for WPBakery Builder <= 1.4.4.1 - Missing Authorization Checks

medium

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the A...

CVSS:
6.3
Affected:
up to 1.4.4.1
Fixed in:
1.4.4.2
Disclosed:
Jul 6, 2022

Web and WooCommerce Addons for WPBakery Builder [vc-addons-by-bit14] < 1.4.4.1 (closed)

unknown

The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.4.1 due to missing capability checks on various functions called via AJAX actions. This makes it possible for any authenticated user, such as a subscriber, to execute the A...

Affected:
up to 1.4.4.1
Fixed in:
1.4.4.1
Disclosed:
Jul 6, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database