๐Ÿ” CVE Alert

CVE-2026-81429

HIGH 7.1

Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.

Vendor unknown
Product export & import wpbakery page builder
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown export & import wpbakery page builder

Be the first to know when new high vulnerabilities affecting unknown export & import wpbakery page builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Export & Import WPBakery Page Builder
0 โ‰ค 1.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/48f67510-9fb3-4f74-a38e-31635617ba60/

Credits

Suhayb Ahmed (cyboltx) WPScan