CVE-2025-68574: WordPress WPBakery Visual Composer WHMCS Elements plugin <= 1.0.4.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68574?
CVE-2025-68574 is a high-severity vulnerability that allows for DOM-Based Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-68574?
To fix CVE-2025-68574, update the WPBakery Visual Composer WHMCS Elements plugin to the latest version.
What are the potential impacts of CVE-2025-68574?
The potential impacts of CVE-2025-68574 include unauthorized access to user data and malicious script execution in the browser.
Which versions of WPBakery Visual Composer WHMCS Elements are affected by CVE-2025-68574?
CVE-2025-68574 affects all versions of WPBakery Visual Composer WHMCS Elements from n/a up to and including version 1.0.4.3.
Is CVE-2025-68574 a known vulnerability?
Yes, CVE-2025-68574 is a known vulnerability documented by security researchers.