CVE-2025-11161: WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vccustomheading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes in the fontcontainer parameter. This makes it possible for authenticated attackers with contributor-level access or higher to inject arbitrary web scripts in posts that will execute whenever a user accesses an injected page via the vccustomheading shortcode with malicious tag and text attributes granted they have access to use WPBakery shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11161?
CVE-2025-11161 is classified as a high severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-11161?
To fix CVE-2025-11161, upgrade the WPBakery Page Builder plugin to version 8.6.2 or later.
What are the risks associated with CVE-2025-11161?
The risks associated with CVE-2025-11161 include unauthorized access to user accounts and the execution of malicious scripts on affected sites.
Which versions of WPBakery Page Builder are affected by CVE-2025-11161?
Versions of WPBakery Page Builder up to and including 8.6.1 are affected by CVE-2025-11161.
What is the primary issue in CVE-2025-11161?
The primary issue in CVE-2025-11161 is insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes.