CVE-2025-47659: WordPress WPBakery Visual Composer WHMCS Elements plugin <= 1.0.4.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements allows Stored XSS. This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through 1.0.4.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows Stored XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47659?
CVE-2025-47659 has a severity rating that could allow for serious security risks due to stored Cross-site Scripting (XSS) vulnerabilities.
How do I fix CVE-2025-47659?
To fix CVE-2025-47659, upgrade WPBakery Visual Composer WHMCS Elements to version 1.0.4.2 or later to mitigate the vulnerability.
What type of vulnerability is CVE-2025-47659?
CVE-2025-47659 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
Which versions are affected by CVE-2025-47659?
CVE-2025-47659 affects WPBakery Visual Composer WHMCS Elements versions up to and including 1.0.4.1.
What can attackers do with CVE-2025-47659?
Attackers can exploit CVE-2025-47659 to execute malicious scripts in the context of users who visit the compromised web page.