CVE-2025-10006 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, an…
Medium CVSS: 6.4

CVE-2025-10006

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when RevSlider is also installed.
Vendor
Wpbakery
Product
Page Builder
CWE
CWE-79
Yayın Tarihi
2025-10-18 07:15:33
Güncelleme
2025-11-26 14:52:05
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar